VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 320 of 471
  • CVE-2023-20974MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2023-20973MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-25862MedMar 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-24862MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Secure Channel Denial of Service Vulnerability

  • CVE-2022-47458MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-47456MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-47455MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2023-1018MedFeb 28, 2023
    risk 0.36cvss 5.5epss 0.06

    An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.

  • CVE-2023-23502MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, tvOS 16.3, watchOS 9.3. An app may be able to determine kernel memory layout.

  • CVE-2022-46440MedFeb 24, 2023
    risk 0.36cvss 5.5epss 0.00

    ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.

  • CVE-2021-33367MedFeb 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.

  • CVE-2023-22233MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-22231MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-21620MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2023-21583MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-21578MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2023-21577MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2023-21714MedFeb 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft Office Information Disclosure Vulnerability

  • CVE-2023-21687MedFeb 14, 2023
    risk 0.36cvss 5.5epss 0.00

    HTTP.sys Information Disclosure Vulnerability

  • CVE-2022-47363MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.