VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 288 of 472
  • CVE-2026-20829MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

  • CVE-2025-14421MedDec 23, 2025
    risk 0.36cvss 5.5epss 0.00

    pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of pdfforge PDF Architect. User interaction is required to exploit this…

  • CVE-2025-14411MedDec 23, 2025
    risk 0.36cvss 5.5epss 0.00

    Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in…

  • CVE-2025-14410MedDec 23, 2025
    risk 0.36cvss 5.5epss 0.00

    Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in…

  • CVE-2025-36921MedDec 11, 2025
    risk 0.36cvss 5.5epss 0.00

    In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

  • CVE-2025-62468MedDec 9, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

  • CVE-2025-48622MedDec 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-61845MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2025-61844MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2025-61843MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2025-61841MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive memory information. Exploitation of this issue requires user interaction in that a…

  • CVE-2025-61840MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2025-60706MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

  • CVE-2025-59513MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.

  • CVE-2025-31937MedNov 11, 2025
    risk 0.36cvss 5.6epss 0.00

    Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result…

  • CVE-2025-43377MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to cause a denial-of-service.

  • CVE-2025-54269MedOct 15, 2025
    risk 0.36cvss 5.5epss 0.00

    Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user…

  • CVE-2025-55695MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.

  • CVE-2025-20724MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418894; Issue ID: MSV-3475.

  • CVE-2025-54237MedSep 16, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a…