VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 247 of 472
  • CVE-2019-2147MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116474108

  • CVE-2019-2146MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112859714

  • CVE-2019-2145MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112858430

  • CVE-2019-2144MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112856493

  • CVE-2019-2143MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-114746174

  • CVE-2019-2142MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112768568

  • CVE-2019-2139MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117610049

  • CVE-2019-2138MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118494320

  • CVE-2019-2079MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115509210

  • CVE-2019-2060MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112709994

  • CVE-2018-21016MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • CVE-2019-16166MedSep 9, 2019
    risk 0.42cvss 6.5epss 0.01

    GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.

  • CVE-2015-9383MedSep 3, 2019
    risk 0.42cvss 6.5epss 0.02

    FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

  • CVE-2015-9382MedSep 3, 2019
    risk 0.42cvss 6.5epss 0.02

    FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

  • CVE-2019-15531MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

  • CVE-2019-2129MedAug 20, 2019
    risk 0.42cvss 6.5epss 0.01

    In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2019-14492HigAug 1, 2019
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

  • CVE-2019-14380MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

  • CVE-2019-10129MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack.…

  • CVE-2019-14370MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.