VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 287 of 472
  • CVE-2026-21348MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21355MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction…

  • CVE-2026-21340MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21339MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21337MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21332MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21319MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in…

  • CVE-2026-21317MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in…

  • CVE-2026-21315MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that…

  • CVE-2026-21314MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in…

  • CVE-2026-21313MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in…

  • CVE-2026-21261MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-21258MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-46306MedJan 28, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafted Keynote file may disclose memory contents.

  • CVE-2026-23951MedJan 22, 2026
    risk 0.36cvss 5.5epss 0.00

    SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 records, causing an integer underflow in the size calculation. This bug exists in PalmDbReader::GetRecord when opening a crafted…

  • CVE-2026-21303MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21302MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21308MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-21278MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2026-20835MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.