VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 23 of 467
  • CVE-2022-41581CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2021-46840CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2021-46839CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2021-40019CriSep 16, 2022
    risk 0.59cvss 9.1epss 0.01

    Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-33643CriAug 10, 2022
    risk 0.59cvss 9.1epss 0.02

    An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

  • CVE-2022-34029CriJul 18, 2022
    risk 0.59cvss 9.1epss 0.01

    Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.

  • CVE-2021-3643CriMay 2, 2022
    risk 0.59cvss 9.1epss 0.02

    A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.

  • CVE-2021-33293CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.02

    Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.

  • CVE-2021-43302CriFeb 16, 2022
    risk 0.59cvss 9.1epss 0.02

    Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when the filename is shorter than 4 characters.

  • CVE-2021-24043CriFeb 2, 2022
    risk 0.59cvss 9.1epss 0.01

    A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if…

  • CVE-2022-23097CriJan 28, 2022
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

  • CVE-2022-23096CriJan 28, 2022
    risk 0.59cvss 9.1epss 0.03

    An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.

  • CVE-2021-37051CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.

  • CVE-2021-37042CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-37041CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-37016CriNov 23, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.

  • CVE-2021-25487HigKEVOct 6, 2021
    risk 0.59cvss 7.3epss 0.01

    Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

  • CVE-2020-19751CriSep 7, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.

  • CVE-2021-38564CriAug 11, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows an out-of-bounds read via util.scand.

  • CVE-2021-36159CriAug 3, 2021
    risk 0.59cvss 9.1epss 0.03

    libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It…