VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 229 of 472
  • CVE-2025-20659MedApr 7, 2025
    risk 0.42cvss 6.5epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-27788HigMar 12, 2025
    risk 0.42cvss 7.5epss 0.01

    JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No…

  • CVE-2025-21254MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

  • CVE-2025-21216MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

  • CVE-2025-21212MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

  • CVE-2025-24162MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2024-54478MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an…

  • CVE-2024-36504MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a…

  • CVE-2025-21600MedJan 9, 2025
    risk 0.42cvss 6.5epss 0.00

    An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a…

  • CVE-2020-9211MedDec 27, 2024
    risk 0.42cvss 6.4epss 0.00

    There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability…

  • CVE-2024-54109MedDec 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54108MedDec 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-52545MedDec 3, 2024
    risk 0.42cvss 6.5epss 0.01

    An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

  • CVE-2018-9429MedDec 2, 2024
    risk 0.42cvss 6.5epss 0.00

    In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2018-9423MedDec 2, 2024
    risk 0.42cvss 6.5epss 0.00

    In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-35371HigNov 29, 2024
    risk 0.42cvss 7.5epss 0.01

    Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive…

  • CVE-2018-9353MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2018-9351MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2018-9350MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2018-9349MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.