VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 306 of 471
  • CVE-2024-26970MedMay 1, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-ipq6018: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in…

  • CVE-2024-26896MedApr 17, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix memory leak when starting AP Kmemleak reported this error: unreferenced object 0xd73d1180 (size 184): comm "wpa_supplicant", pid 1559, jiffies 13006305 (age 964.245s) hex dump…

  • CVE-2024-20796MedApr 11, 2024
    risk 0.36cvss 5.5epss 0.00

    Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2024-20798MedApr 11, 2024
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2024-20771MedApr 11, 2024
    risk 0.36cvss 5.5epss 0.00

    Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2021-47210MedApr 10, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps6598x_block_read with a higher than allowed len can be handled by just returning an error. There's no need to crash systems with panic-on-warn…

  • CVE-2024-20770MedApr 10, 2024
    risk 0.36cvss 5.5epss 0.00

    Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2024-20766MedApr 10, 2024
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2024-20737MedApr 10, 2024
    risk 0.36cvss 5.5epss 0.00

    After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2024-28902MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-28901MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-28900MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-26255MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-26217MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-26207MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

  • CVE-2024-26172MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows DWM Core Library Information Disclosure Vulnerability

  • CVE-2024-29782MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29750MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29744MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29742MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.