VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 36 of 467
  • CVE-2025-0904HigFeb 11, 2025
    risk 0.57cvss 8.8epss 0.01

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability…

  • CVE-2025-0902HigFeb 11, 2025
    risk 0.57cvss 8.8epss 0.01

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability…

  • CVE-2025-0901HigFeb 11, 2025
    risk 0.57cvss 8.8epss 0.01

    PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-0437HigJan 15, 2025
    risk 0.57cvss 8.8epss 0.00

    Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-21246HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2025-21245HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2025-21178HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2024-12693HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2018-9365HigNov 19, 2024
    risk 0.57cvss 8.8epss 0.00

    In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-10467HigOct 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2024-47721HigOct 21, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: remove unused C2H event ID RTW89_MAC_C2H_FUNC_READ_WOW_CAM to prevent out-of-bounds reading The handler of firmware C2H event RTW89_MAC_C2H_FUNC_READ_WOW_CAM isn't implemented, but driver expects…

  • CVE-2024-37338HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-43110HigSep 5, 2024
    risk 0.57cvss 8.8epss 0.00

    The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically…

  • CVE-2024-7966HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-48871HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tty: serial: qcom-geni-serial: fix slab-out-of-bounds on RX FIFO buffer Driver's probe allocates memory for RX FIFO (port->rx_fifo) based on default RX FIFO depth, e.g. 16. Later during serial startup the…

  • CVE-2024-7522HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7255HigAug 1, 2024
    risk 0.57cvss 8.8epss 0.01

    Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-39882HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of…

  • CVE-2024-6102HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-30068HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability