VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 340 of 471
  • CVE-2020-25770MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24565MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24564MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-0365MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137346580

  • CVE-2020-0359MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0329MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…

  • CVE-2020-0323MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0125MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0427MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2020-0393MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-16855MedSep 11, 2020
    risk 0.36cvss 5.5epss 0.04

    An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.…

  • CVE-2020-3674MedSep 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Nicobar, QCS405, Saipan,…

  • CVE-2020-9096MedAug 21, 2020
    risk 0.36cvss 5.5epss 0.00

    HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious…

  • CVE-2020-24348MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.00

    njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.

  • CVE-2020-24347MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.00

    njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.

  • CVE-2020-8682MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.00

    Out of bounds read in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-16211MedAug 6, 2020
    risk 0.36cvss 5.5epss 0.01

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

  • CVE-2020-9649MedJul 17, 2020
    risk 0.36cvss 5.5epss 0.03

    Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2020-1342MedJul 14, 2020
    risk 0.36cvss 5.5epss 0.06

    An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from…

  • CVE-2020-9557MedJun 26, 2020
    risk 0.36cvss 5.5epss 0.03

    Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.