VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 242 of 472
  • CVE-2020-12418MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.03

    Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

  • CVE-2020-12407MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox <…

  • CVE-2020-11905MedJun 17, 2020
    risk 0.42cvss 6.5epss 0.02

    The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.

  • CVE-2020-11903MedJun 17, 2020
    risk 0.42cvss 6.5epss 0.02

    The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.

  • CVE-2020-0212MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0211MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0207MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0205MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-0200MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-0193MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed…

  • CVE-2020-0192MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-0191MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0182MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0180MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0127MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-9071MedJun 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device.…

  • CVE-2020-11018MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.02

    In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.

  • CVE-2020-13439MedMay 24, 2020
    risk 0.42cvss 6.5epss 0.01

    ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.

  • CVE-2020-13438MedMay 24, 2020
    risk 0.42cvss 6.5epss 0.01

    ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.

  • CVE-2020-11522MedMay 15, 2020
    risk 0.42cvss 6.5epss 0.03

    libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.