VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,410)

page 371 of 471
  • CVE-2025-20655MedApr 7, 2025
    risk 0.34cvss 5.3epss 0.00

    In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID:…

  • CVE-2025-23406MedFeb 14, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.

  • CVE-2024-24911MedFeb 6, 2025
    risk 0.34cvss 5.3epss 0.00

    In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL…

  • CVE-2025-20891MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2025-20887MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2024-54518MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.

  • CVE-2024-48855MedJan 14, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

  • CVE-2024-51471MedDec 19, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.

  • CVE-2024-54937MedDec 9, 2024
    risk 0.34cvss 5.3epss 0.00

    A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.

  • CVE-2024-46891MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of logged events to exhaust the…

  • CVE-2024-31198MedSep 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

  • CVE-2023-20509MedAug 13, 2024
    risk 0.34cvss 5.2epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.

  • CVE-2024-21143MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-36124MedJun 3, 2024
    risk 0.34cvss 5.3epss 0.00

    iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and…

  • CVE-2024-23808MedMay 7, 2024
    risk 0.34cvss 5.2epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.

  • CVE-2024-28894MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.

  • CVE-2024-22006MedMar 11, 2024
    risk 0.34cvss 5.3epss 0.00

    OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.

  • CVE-2023-52365MedFeb 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-0016MedFeb 16, 2024
    risk 0.34cvss 5.3epss 0.00

    In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-4693MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI…