VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 265 of 472
  • CVE-2025-46591MedMay 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-20944MedApr 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

  • CVE-2024-38417MedFeb 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while processing IO control commands.

  • CVE-2024-38416MedFeb 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure during audio playback.

  • CVE-2024-38414MedFeb 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while processing information on firmware image during core initialization.

  • CVE-2025-21647HigJan 19, 2025
    risk 0.40cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-host bulk flow…

  • CVE-2024-43063MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    information disclosure while invoking the mailbox read API.

  • CVE-2024-33067MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

  • CVE-2024-20136MedDec 2, 2024
    risk 0.40cvss 6.2epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.

  • CVE-2024-20107MedNov 4, 2024
    risk 0.40cvss 6.2epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.

  • CVE-2024-39434MedSep 27, 2024
    risk 0.40cvss 6.2epss 0.00

    In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2024-46743HigSep 18, 2024
    risk 0.40cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells property), KASAN…

  • CVE-2023-28074MedJul 31, 2024
    risk 0.40cvss 6.2epss 0.00

    Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2023-43528MedMay 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

  • CVE-2024-29754MedApr 5, 2024
    risk 0.40cvss 6.2epss 0.00

    In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-28579MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_Unload() function when reading images in HDR format.

  • CVE-2024-28319MedMar 15, 2024
    risk 0.40cvss 6.2epss 0.00

    gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374

  • CVE-2024-22007MedMar 11, 2024
    risk 0.40cvss 6.2epss 0.00

    In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-26334MedMar 5, 2024
    risk 0.40cvss 6.2epss 0.00

    swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

  • CVE-2024-20949MedFeb 17, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…