VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 291 of 472
  • CVE-2025-30313MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-27165MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43584MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-47135MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in…

  • CVE-2025-49658MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.

  • CVE-2025-48812MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-43587MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2025-21168MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2025-21167MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2025-21009MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-21008MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-20692MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418040; Issue ID: MSV-3476.

  • CVE-2025-20691MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418039; Issue ID: MSV-3477.

  • CVE-2025-20690MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418038; Issue ID: MSV-3478.

  • CVE-2025-20689MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418048; Issue ID: MSV-3479.

  • CVE-2025-20688MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418047; Issue ID: MSV-3480.

  • CVE-2025-20687MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418045; Issue ID: MSV-3481.

  • CVE-2025-47112MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of…

  • CVE-2025-43578MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of…

  • CVE-2025-2884MedJun 10, 2025
    risk 0.36cvss 6.6epss 0.00

    TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0