VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 286 of 472
  • CVE-2025-46280MedMay 26, 2026
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.

  • CVE-2026-43996MedMay 14, 2026
    risk 0.36cvss 5.5epss 0.00

    OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, the bounds check in TGAInput::decode_pixel computes k + palbytespp as unsigned 32-bit arithmetic. When k = 0xFFFFFFFC…

  • CVE-2026-35419MedMay 12, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

  • CVE-2026-34663MedMay 12, 2026
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user…

  • CVE-2026-42481MedMay 1, 2026
    risk 0.36cvss 5.5epss 0.00

    Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can be triggered by crafted IGES or STEP files. These issues include an out-of-bounds read in Geom2d_BSplineCurve::EvalD0 during IGES B-spline curve evaluation, an…

  • CVE-2026-42480MedMay 1, 2026
    risk 0.36cvss 5.5epss 0.00

    A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because the quoted-string escape handler uses…

  • CVE-2026-42479MedMay 1, 2026
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because coordIndex values from parsed input are used as…

  • CVE-2026-33450MedApr 30, 2026
    risk 0.36cvss 5.5epss 0.00

    CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.

  • CVE-2026-27931MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-27930MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-28890MedMar 25, 2026
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.

  • CVE-2026-27270MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-27268MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-27219MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-27216MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21365MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-25180MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

  • CVE-2026-24282MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

  • CVE-2026-20675MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may…

  • CVE-2024-56807MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming…