VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 38 of 467
  • CVE-2023-25668CriMar 25, 2023
    risk 0.57cvss 9.8epss 0.01

    TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and…

  • CVE-2023-28445CriMar 24, 2023
    risk 0.57cvss 9.9epss 0.01

    Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in…

  • CVE-2023-1534HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1532HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-24872HigMar 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-26489CriMar 8, 2023
    risk 0.57cvss 9.9epss 0.01

    wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective…

  • CVE-2023-21798HigFeb 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-0698HigFeb 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-20610HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.01

    In cellular modem firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:…

  • CVE-2022-46344HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on…

  • CVE-2022-45313HigDec 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.

  • CVE-2022-1738HigOct 19, 2022
    risk 0.57cvss 8.7epss 0.01

    Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to leak sensitive data from the process memory.

  • CVE-2022-32912HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-40320HigSep 9, 2022
    risk 0.57cvss 8.8epss 0.01

    cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.

  • CVE-2022-34300HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

  • CVE-2020-35632HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35631HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35630HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35629HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-28635HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…