VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 237 of 472
  • CVE-2022-35481MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.

  • CVE-2022-35479MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.

  • CVE-2022-35478MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.

  • CVE-2022-35477MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.

  • CVE-2022-35476MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.

  • CVE-2022-35100MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via gfxline_getbbox at /lib/gfxtools.c.

  • CVE-2022-2605MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-20346MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.00

    In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-1858MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.

  • CVE-2022-34037HigJul 22, 2022
    risk 0.42cvss 7.5epss 0.01

    An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged…

  • CVE-2022-20221MedJul 13, 2022
    risk 0.42cvss 6.5epss 0.00

    In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-32325MedJul 1, 2022
    risk 0.42cvss 6.5epss 0.01

    JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.

  • CVE-2022-32141MedJun 24, 2022
    risk 0.42cvss 6.5epss 0.01

    Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.

  • CVE-2022-32139MedJun 24, 2022
    risk 0.42cvss 6.5epss 0.01

    In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.

  • CVE-2022-30045MedMay 17, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

  • CVE-2022-20010MedMay 10, 2022
    risk 0.42cvss 6.5epss 0.00

    In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-27406HigApr 22, 2022
    risk 0.42cvss 7.5epss 0.03

    FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

  • CVE-2022-27405HigApr 22, 2022
    risk 0.42cvss 7.5epss 0.03

    FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.

  • CVE-2021-40425MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…

  • CVE-2021-40424MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…