VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 337 of 471
  • CVE-2021-0563MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0562MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0556MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-11265MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking

  • CVE-2021-3522MedJun 2, 2021
    risk 0.36cvss 5.5epss 0.05

    GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.

  • CVE-2020-27824MedMay 13, 2021
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

  • CVE-2021-31174MedMay 11, 2021
    risk 0.36cvss 5.5epss 0.03

    Microsoft Excel Information Disclosure Vulnerability

  • CVE-2021-31471MedMay 7, 2021
    risk 0.36cvss 5.5epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2021-0471MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1791MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and…

  • CVE-2021-1778MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a…

  • CVE-2020-29639MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font may result in the disclosure of process memory.

  • CVE-2020-29615MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to…

  • CVE-2020-29610MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may…

  • CVE-2020-29608MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave,…

  • CVE-2021-3477MedMar 31, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this…

  • CVE-2020-7853MedMar 24, 2021
    risk 0.36cvss 5.5epss 0.01

    An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker can exploit arbitrary code execution.

  • CVE-2021-0463MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-0394MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-28394MedFeb 9, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of RAS files. This could result in a memory access past the end of an…