VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 235 of 472
  • CVE-2023-35316MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Remote Procedure Call Runtime Information Disclosure Vulnerability

  • CVE-2023-35314MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Remote Procedure Call Runtime Denial of Service Vulnerability

  • CVE-2023-35296MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-33164MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Remote Procedure Call Runtime Denial of Service Vulnerability

  • CVE-2023-32035MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Remote Procedure Call Runtime Denial of Service Vulnerability

  • CVE-2023-32034MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Remote Procedure Call Runtime Denial of Service Vulnerability

  • CVE-2023-32402MedJun 23, 2023
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.

  • CVE-2023-0668MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

  • CVE-2023-32206MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2023-25738MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on…

  • CVE-2023-23528MedMay 8, 2023
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted Bluetooth packet may result in disclosure of process memory.

  • CVE-2022-43681MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet,…

  • CVE-2022-40318MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible…

  • CVE-2022-40302MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible…

  • CVE-2023-27353MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msprox endpoint. The issue results…

  • CVE-2023-24513MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…

  • CVE-2023-29417MedApr 6, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space to be filled with decompressed data. NOTE: the vendor's perspective is that the observed behavior…

  • CVE-2023-1819MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-25659HigMar 25, 2023
    risk 0.42cvss 7.5epss 0.00

    TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in TensorFlow version 2.12.0 and…

  • CVE-2023-25658HigMar 25, 2023
    risk 0.42cvss 7.5epss 0.00

    TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.