VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 266 of 472
  • CVE-2024-20941MedFeb 17, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: HTML UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-1140MedFeb 13, 2024
    risk 0.40cvss 6.1epss 0.00

    Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.

  • CVE-2023-33065MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure in Audio while accessing AVCS services from ADSP payload.

  • CVE-2023-40549MedJan 29, 2024
    risk 0.40cvss 6.2epss 0.00

    An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.

  • CVE-2023-39193MedOct 9, 2023
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.

  • CVE-2023-28571MedOct 3, 2023
    risk 0.40cvss 6.1epss 0.00

    Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.

  • CVE-2023-1916MedApr 10, 2023
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue…

  • CVE-2023-0187MedApr 1, 2023
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.

  • CVE-2022-31616MedNov 19, 2022
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information disclosure.

  • CVE-2022-26369MedNov 11, 2022
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

  • CVE-2020-36602MedSep 20, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message,…

  • CVE-2022-28681MedJul 18, 2022
    risk 0.40cvss 6.1epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2021-44768MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

  • CVE-2021-44479MedDec 1, 2021
    risk 0.40cvss 6.1epss 0.00

    NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

  • CVE-2021-40154MedDec 1, 2021
    risk 0.40cvss 6.1epss 0.01

    NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

  • CVE-2021-28614MedAug 24, 2021
    risk 0.40cvss 6.1epss 0.02

    Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information and cause a denial of service in the…

  • CVE-2021-28612MedAug 24, 2021
    risk 0.40cvss 6.1epss 0.02

    Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information and cause a denial of service in the…

  • CVE-2021-28616MedAug 24, 2021
    risk 0.40cvss 6.1epss 0.02

    Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information and cause a denial of service in the…

  • CVE-2021-28611MedAug 24, 2021
    risk 0.40cvss 6.1epss 0.02

    Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information and cause a denial of service in the…

  • CVE-2021-37664HigAug 12, 2021
    risk 0.40cvss 7.3epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `BoostedTreesSparseCalculateBestFeatureSplit`. The…