VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 243 of 472
  • CVE-2020-7067HigApr 27, 2020
    risk 0.42cvss 7.5epss 0.04

    In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

  • CVE-2020-10844MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).

  • CVE-2019-2058MedMar 15, 2020
    risk 0.42cvss 6.5epss 0.01

    In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android Versions: Android-10 Android ID: A-136089102

  • CVE-2015-7506MedFeb 18, 2020
    risk 0.42cvss 6.5epss 0.01

    The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.

  • CVE-2019-20454HigFeb 14, 2020
    risk 0.42cvss 7.5epss 0.02

    An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash…

  • CVE-2020-6405MedFeb 11, 2020
    risk 0.42cvss 6.5epss 0.03

    Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-6395MedFeb 11, 2020
    risk 0.42cvss 6.5epss 0.02

    Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-20387HigJan 21, 2020
    risk 0.42cvss 7.5epss 0.02

    repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

  • CVE-2019-20200MedDec 31, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature.

  • CVE-2019-20199MedDec 31, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer.

  • CVE-2019-20020MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.

  • CVE-2019-20018MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.

  • CVE-2019-20017MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.

  • CVE-2019-20005MedDec 26, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\0' character (where the…

  • CVE-2019-19957MedDec 24, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.

  • CVE-2019-19944MedDec 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

  • CVE-2019-8615MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary…

  • CVE-2019-8607MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the…

  • CVE-2019-8517MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted font may result in the disclosure of process memory.

  • CVE-2019-5278MedDec 13, 2019
    risk 0.42cvss 6.5epss 0.01

    There is an out-of-bounds read vulnerability in the Advanced Packages feature of the Gauss100 OLTP database in CampusInsight before V100R019C00SPC200. Attackers who gain the specific permission can use this vulnerability by sending elaborate SQL statements to the database.…