VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 316 of 471
  • CVE-2023-32354MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. An app may be able to disclose kernel memory.

  • CVE-2023-33139MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Visual Studio Information Disclosure Vulnerability

  • CVE-2023-21118MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21112MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20706MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.

  • CVE-2023-20703MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853.

  • CVE-2023-29279MedMay 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2023-29277MedMay 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2022-21239MedMay 10, 2023
    risk 0.36cvss 5.6epss 0.00

    Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-30084MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in util/decompile.c.

  • CVE-2023-27929MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing a maliciously crafted image may result in disclosure of process memory.

  • CVE-2023-29942MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.

  • CVE-2023-29941MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.

  • CVE-2023-29939MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).

  • CVE-2023-29934MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().

  • CVE-2023-29933MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.

  • CVE-2023-21080MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20935MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-26403MedApr 12, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2023-26385MedApr 12, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…