CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 234 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42862 | Med | 0.42 | 6.5 | 0.01 | Jan 10, 2024 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing an image may result in disclosure of process memory. | ||
| CVE-2023-47993 | Med | 0.42 | 6.5 | 0.01 | Jan 9, 2024 | A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service. | ||
| CVE-2024-21314 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2024-20660 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2023-6204 | Med | 0.42 | 6.5 | 0.01 | Nov 21, 2023 | On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | ||
| CVE-2023-28376 | Med | 0.42 | 6.5 | 0.00 | Nov 14, 2023 | Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | ||
| CVE-2023-21315 | Med | 0.42 | 6.5 | 0.00 | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-45662 | Med | 0.42 | 6.5 | 0.01 | Oct 21, 2023 | stb_image is a single file MIT licensed library for processing images. When `stbi_set_flip_vertically_on_load` is set to `TRUE` and `req_comp` is set to a number that doesn’t match the real number of components per pixel, the library attempts to flip the image vertically. A… | ||
| CVE-2023-45661 | Med | 0.42 | 6.5 | 0.01 | Oct 21, 2023 | stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to… | ||
| CVE-2023-43785 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2023 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system. | ||
| CVE-2023-42755 | Med | 0.42 | 6.5 | 0.00 | Oct 5, 2023 | A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system… | ||
| CVE-2023-42821 | Hig | 0.42 | 7.5 | 0.01 | Sep 22, 2023 | The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input… | ||
| CVE-2023-4527 | Med | 0.42 | 6.5 | 0.02 | Sep 18, 2023 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function… | ||
| CVE-2023-21667 | Med | 0.42 | 6.5 | 0.00 | Sep 5, 2023 | Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. | ||
| CVE-2023-20848 | Med | 0.42 | 6.5 | 0.00 | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433. | ||
| CVE-2023-20840 | Med | 0.42 | 6.5 | 0.00 | Sep 4, 2023 | In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID:… | ||
| CVE-2023-39685 | Hig | 0.42 | 7.5 | 0.01 | Sep 1, 2023 | An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string. | ||
| CVE-2023-3425 | Med | 0.42 | 6.5 | 0.01 | Aug 25, 2023 | Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory. | ||
| CVE-2023-35319 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-35318 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability |
- risk 0.42cvss 6.5epss 0.01
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing an image may result in disclosure of process memory.
- risk 0.42cvss 6.5epss 0.01
A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- risk 0.42cvss 6.5epss 0.00
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.42cvss 6.5epss 0.01
stb_image is a single file MIT licensed library for processing images. When `stbi_set_flip_vertically_on_load` is set to `TRUE` and `req_comp` is set to a number that doesn’t match the real number of components per pixel, the library attempts to flip the image vertically. A…
- risk 0.42cvss 6.5epss 0.01
stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to…
- risk 0.42cvss 6.5epss 0.01
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
- risk 0.42cvss 6.5epss 0.00
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system…
- risk 0.42cvss 7.5epss 0.01
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input…
- risk 0.42cvss 6.5epss 0.02
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function…
- risk 0.42cvss 6.5epss 0.00
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
- risk 0.42cvss 6.5epss 0.00
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.
- risk 0.42cvss 6.5epss 0.00
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID:…
- risk 0.42cvss 7.5epss 0.01
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability