VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 324 of 471
  • CVE-2022-20513MedDec 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-42851MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.

  • CVE-2022-32916MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 16. An app may be able to disclose kernel memory.

  • CVE-2022-20471MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-44648MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.01

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-44647MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.01

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-42781MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42780MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42779MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42774MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42773MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42762MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42761MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42759MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-39130MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39320MedNov 16, 2022
    risk 0.36cvss 5.5epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of…

  • CVE-2022-32602MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790; Issue ID: ALPS07388790.

  • CVE-2022-32936MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel memory.

  • CVE-2022-44081MedOct 31, 2022
    risk 0.36cvss 5.5epss 0.00

    Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.

  • CVE-2022-39836MedOct 25, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one…