VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 292 of 472
  • CVE-2025-47105MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2025-47104MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2025-33065MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33063MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33062MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33061MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33060MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33059MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33058MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-33055MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-32720MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-32719MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-24069MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-24065MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

  • CVE-2025-29871MedJun 6, 2025
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5…

  • CVE-2025-20988MedJun 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-46716MedMay 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_SetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the pointer the user has passed in…

  • CVE-2025-43551MedMay 13, 2025
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2025-31196MedMay 12, 2025
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may…

  • CVE-2025-20976MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.