CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 230 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-13320 | Med | 0.42 | 6.5 | 0.00 | Nov 27, 2024 | In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2024-51569 | Hig | 0.42 | 7.5 | 0.01 | Nov 26, 2024 | Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus… | ||
| CVE-2018-9486 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2018-9485 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2018-9483 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2018-9482 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2018-9481 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2018-9480 | Med | 0.42 | 6.5 | 0.00 | Nov 20, 2024 | In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2018-9371 | Med | 0.42 | 6.4 | 0.00 | Nov 19, 2024 | In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with… | ||
| CVE-2024-24425 | Med | 0.42 | 6.5 | 0.00 | Nov 15, 2024 | Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | ||
| CVE-2024-51565 | Med | 0.42 | 6.5 | 0.00 | Nov 12, 2024 | The hda driver is vulnerable to a buffer over-read from a guest-controlled value. | ||
| CVE-2024-51562 | Med | 0.42 | 6.5 | 0.00 | Nov 12, 2024 | The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value. | ||
| CVE-2024-10464 | Med | 0.42 | 6.5 | 0.01 | Oct 29, 2024 | Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and… | ||
| CVE-2024-43561 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43558 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43557 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43555 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43542 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43540 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43538 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
- risk 0.42cvss 6.5epss 0.00
In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.42cvss 7.5epss 0.01
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus…
- risk 0.42cvss 6.5epss 0.00
In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.00
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.00
In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.00
In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.00
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.00
In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.42cvss 6.4epss 0.00
In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with…
- risk 0.42cvss 6.5epss 0.00
Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
- risk 0.42cvss 6.5epss 0.00
The hda driver is vulnerable to a buffer over-read from a guest-controlled value.
- risk 0.42cvss 6.5epss 0.00
The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.
- risk 0.42cvss 6.5epss 0.01
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and…
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability