VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 238 of 472
  • CVE-2021-39805MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.00

    In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-0806MedApr 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.

  • CVE-2022-0792MedApr 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-20295MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.00

    It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was…

  • CVE-2022-26280MedMar 28, 2022
    risk 0.42cvss 6.5epss 0.02

    Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.

  • CVE-2021-34342MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.

  • CVE-2021-34341MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.

  • CVE-2021-34340MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

  • CVE-2021-34339MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

  • CVE-2021-34338MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

  • CVE-2022-24370MedFeb 18, 2022
    risk 0.42cvss 6.5epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…

  • CVE-2021-35452MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.

  • CVE-2021-0976MedDec 15, 2021
    risk 0.42cvss 6.5epss 0.01

    In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android…

  • CVE-2021-0650MedDec 15, 2021
    risk 0.42cvss 6.5epss 0.01

    In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-36134MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.

  • CVE-2021-39995MedNov 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS…

  • CVE-2020-16048MedNov 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in ANGLE allowed a remote attacker to obtain sensitive data via a crafted HTML page.

  • CVE-2021-0632MedOct 25, 2021
    risk 0.42cvss 6.5epss 0.00

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker under certain build conditions with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-20836MedOct 19, 2021
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project files.

  • CVE-2021-32029MedOct 8, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.