VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 233 of 472
  • CVE-2024-21457MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    INformation disclosure while handling Multi-link IE in beacon frame.

  • CVE-2024-21456MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure while parsing beacon frame in STA.

  • CVE-2024-3017MedJun 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary…

  • CVE-2024-5268MedJun 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to…

  • CVE-2023-43537MedJun 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling T2LM Action Frame in WLAN Host.

  • CVE-2023-46280MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17…

  • CVE-2024-29857HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during…

  • CVE-2024-4059MedMay 1, 2024
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-25569MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-23533MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.

  • CVE-2024-3839MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-3855MedApr 16, 2024
    risk 0.42cvss 6.5epss 0.00

    In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

  • CVE-2024-21618MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause Denial of Service (DoS). On all Junos OS and Junos OS Evolved…

  • CVE-2024-26226MedApr 9, 2024
    risk 0.42cvss 6.5epss 0.02

    Windows Distributed File System (DFS) Information Disclosure Vulnerability

  • CVE-2024-2626MedMar 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-0045MedMar 11, 2024
    risk 0.42cvss 6.5epss 0.00

    In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-41252MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-45231MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.01

    EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

  • CVE-2023-45229MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.01

    EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of…

  • CVE-2023-42865MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing an image may result in disclosure of process memory.