VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 236 of 472
  • CVE-2021-35369MedFeb 24, 2023
    risk 0.42cvss 6.5epss 0.01

    Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filtering_get_contents function.

  • CVE-2022-48293MedFeb 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48292MedFeb 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2023-24977HigFeb 1, 2023
    risk 0.42cvss 7.5epss 0.01

    Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214…

  • CVE-2022-39061MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.01

    ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial…

  • CVE-2022-47881MedJan 18, 2023
    risk 0.42cvss 6.5epss 0.01

    Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.

  • CVE-2022-28285MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When generating the assembly code for MLoadTypedArrayElementHole, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and…

  • CVE-2022-22742MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2022-20468MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-35260MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.02

    curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will…

  • CVE-2022-45315MedDec 5, 2022
    risk 0.42cvss 6.4epss 0.01

    Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.

  • CVE-2022-4144MedNov 29, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious…

  • CVE-2022-31630MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.02

    In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can…

  • CVE-2022-39213HigSep 15, 2022
    risk 0.42cvss 7.5epss 0.01

    go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using `ParseVector`, an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is…

  • CVE-2022-40737MedSep 15, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.

  • CVE-2022-38528MedSep 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component Assimp::XFileImporter::CreateMeshes.

  • CVE-2021-23168MedAug 18, 2022
    risk 0.42cvss 6.5epss 0.00

    Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2022-35485MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.

  • CVE-2022-35483MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.

  • CVE-2022-35482MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.