VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 278 of 472
  • CVE-2024-24452MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

  • CVE-2024-32897MedJun 13, 2024
    risk 0.38cvss 5.9epss 0.00

    In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2024-3859MedApr 16, 2024
    risk 0.38cvss 5.9epss 0.01

    On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-30401MedApr 12, 2024
    risk 0.38cvss 5.9epss 0.01

    An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C, may allow an attacker to exploit a stack-based buffer overflow, leading to a…

  • CVE-2024-29747MedApr 5, 2024
    risk 0.38cvss 5.9epss 0.00

    In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27231MedApr 5, 2024
    risk 0.38cvss 5.9epss 0.00

    In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25392MedMar 27, 2024
    risk 0.38cvss 5.9epss 0.00

    An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.

  • CVE-2024-28756MedMar 21, 2024
    risk 0.38cvss 5.9epss 0.00

    The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.

  • CVE-2024-26000MedMar 12, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

  • CVE-2024-27234MedMar 11, 2024
    risk 0.38cvss 5.9epss 0.00

    In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25989MedMar 11, 2024
    risk 0.38cvss 5.9epss 0.00

    In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22251MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.

  • CVE-2023-39541MedFeb 20, 2024
    risk 0.38cvss 5.9epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-39540MedFeb 20, 2024
    risk 0.38cvss 5.9epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2024-21344MedFeb 13, 2024
    risk 0.38cvss 5.9epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-21343MedFeb 13, 2024
    risk 0.38cvss 5.9epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2023-42538MedNov 7, 2023
    risk 0.38cvss 5.9epss 0.00

    An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-3646MedAug 29, 2023
    risk 0.38cvss 5.9epss 0.01

    On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.

  • CVE-2020-22217MedAug 22, 2023
    risk 0.38cvss 5.9epss 0.01

    Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

  • CVE-2023-33383MedAug 2, 2023
    risk 0.38cvss 5.3epss 0.05

    Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.