VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 37 of 467
  • CVE-2024-5497HigMay 30, 2024
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-5159HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2021-47390HigMay 21, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect() KASAN reports the following issue: BUG: KASAN: stack-out-of-bounds in kvm_make_vcpus_request_mask+0x174/0x440 [kvm] Read of size…

  • CVE-2021-47308HigMay 21, 2024
    risk 0.57cvss 8.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix array index out of bound exception Fix array index out of bound exception in fc_rport_prli_resp().

  • CVE-2024-34200HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.

  • CVE-2024-32614HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

  • CVE-2024-3854HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-28938HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-3159HigApr 6, 2024
    risk 0.57cvss 8.8epss 0.02

    Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3156HigApr 6, 2024
    risk 0.57cvss 8.8epss 0.13

    Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-51395HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.00

    The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2024-1669HigFeb 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4072HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-29373HigJun 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-24924HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2020-36074HigApr 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the title parameter.

  • CVE-2022-24353HigMar 28, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko…

  • CVE-2022-24352HigMar 28, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko kernel module. The…

  • CVE-2022-23124CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper…

  • CVE-2022-23123CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper…