CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 232 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31176 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TableFeaturePropOXM::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31174 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::FeaturesReply::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31173 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyFlow::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31172 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyTable::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31171 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyPort::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31170 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyQueue::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31169 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::QueueGetConfigReply::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31168 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::EchoCommon::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-31166 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2024 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::HelloElemVersionBitmap::unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2024-39775 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-38214 | Med | 0.42 | 6.5 | 0.02 | Aug 13, 2024 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | ||
| CVE-2024-21467 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon probe frame during scan entry generation in client side. | ||
| CVE-2024-21459 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon or probe response frame in STA. | ||
| CVE-2024-40789 | Med | 0.42 | 6.5 | 0.01 | Jul 29, 2024 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to… | ||
| CVE-2024-2884 | Med | 0.42 | 6.5 | 0.00 | Jul 16, 2024 | Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2023-52886 | Med | 0.42 | 6.4 | 0.00 | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280… | ||
| CVE-2024-38102 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2024 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | ||
| CVE-2024-38101 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2024 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | ||
| CVE-2024-38048 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2024 | Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability | ||
| CVE-2024-21458 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information disclosure while handling SA query action frame. |
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TableFeaturePropOXM::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::FeaturesReply::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyFlow::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyTable::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyPort::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyQueue::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::QueueGetConfigReply::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::EchoCommon::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::HelloElemVersionBitmap::unpack. This issue affects libfluid: 0.1.0.
- risk 0.42cvss 6.5epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
- risk 0.42cvss 6.5epss 0.02
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon probe frame during scan entry generation in client side.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon or probe response frame in STA.
- risk 0.42cvss 6.5epss 0.01
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to…
- risk 0.42cvss 6.5epss 0.00
Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.42cvss 6.4epss 0.00
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280…
- risk 0.42cvss 6.5epss 0.01
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling SA query action frame.