CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,413)
page 320 of 471| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20974 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-20973 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-25862 | Med | 0.36 | 5.5 | 0.00 | Mar 22, 2023 | Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue… | ||
| CVE-2023-24862 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Windows Secure Channel Denial of Service Vulnerability | ||
| CVE-2022-47458 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | ||
| CVE-2022-47456 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | ||
| CVE-2022-47455 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | ||
| CVE-2023-1018 | Med | 0.36 | 5.5 | 0.06 | Feb 28, 2023 | An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM. | ||
| CVE-2023-23502 | Med | 0.36 | 5.5 | 0.00 | Feb 27, 2023 | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, tvOS 16.3, watchOS 9.3. An app may be able to determine kernel memory layout. | ||
| CVE-2022-46440 | Med | 0.36 | 5.5 | 0.00 | Feb 24, 2023 | ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c. | ||
| CVE-2021-33367 | Med | 0.36 | 5.5 | 0.00 | Feb 22, 2023 | Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file. | ||
| CVE-2023-22233 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue… | ||
| CVE-2023-22231 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue… | ||
| CVE-2023-21620 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires… | ||
| CVE-2023-21583 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue… | ||
| CVE-2023-21578 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires… | ||
| CVE-2023-21577 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires… | ||
| CVE-2023-21714 | Med | 0.36 | 5.5 | 0.01 | Feb 14, 2023 | Microsoft Office Information Disclosure Vulnerability | ||
| CVE-2023-21687 | Med | 0.36 | 5.5 | 0.00 | Feb 14, 2023 | HTTP.sys Information Disclosure Vulnerability | ||
| CVE-2022-47363 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services. |
- risk 0.36cvss 5.5epss 0.00
In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…
- risk 0.36cvss 5.5epss 0.01
Windows Secure Channel Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- risk 0.36cvss 5.5epss 0.06
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
- risk 0.36cvss 5.5epss 0.00
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, tvOS 16.3, watchOS 9.3. An app may be able to determine kernel memory layout.
- risk 0.36cvss 5.5epss 0.00
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
- risk 0.36cvss 5.5epss 0.00
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
- risk 0.36cvss 5.5epss 0.00
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…
- risk 0.36cvss 5.5epss 0.00
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…
- risk 0.36cvss 5.5epss 0.00
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…
- risk 0.36cvss 5.5epss 0.00
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…
- risk 0.36cvss 5.5epss 0.00
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…
- risk 0.36cvss 5.5epss 0.00
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…
- risk 0.36cvss 5.5epss 0.01
Microsoft Office Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
HTTP.sys Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.