VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 380 of 470
  • CVE-2023-25756MedNov 14, 2023
    risk 0.30cvss 4.6epss 0.00

    Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2023-3497MedJul 3, 2023
    risk 0.30cvss 4.6epss 0.00

    Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)

  • CVE-2023-32391MedJun 23, 2023
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.

  • CVE-2023-28448MedMar 24, 2023
    risk 0.30cvss 5.7epss 0.01

    Versionize is a framework for version tolerant serializion/deserialization of Rust data structures, designed for usecases that need fast deserialization times and minimal size overhead. An issue was discovered in the ‘Versionize::deserialize’ implementation provided by the…

  • CVE-2022-22079MedJan 9, 2023
    risk 0.30cvss 4.6epss 0.00

    Denial of service while processing fastboot flash command on mmc due to buffer over read

  • CVE-2022-39317MedNov 16, 2022
    risk 0.30cvss 4.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been…

  • CVE-2022-20132MedJun 15, 2022
    risk 0.30cvss 4.6epss 0.00

    In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if a malicious USB HID device were plugged in, with no additional execution privileges…

  • CVE-2021-1928MedSep 8, 2021
    risk 0.30cvss 4.6epss 0.00

    Buffer over read could occur due to incorrect check of buffer size while flashing emmc devices in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and…

  • CVE-2021-1901MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    Possible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1899MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-1898MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    Possible buffer over-read due to incorrect overflow check when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1897MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    Possible Buffer Over-read due to lack of validation of boundary checks when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-22306MedFeb 6, 2021
    risk 0.30cvss 4.6epss 0.00

    There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound,…

  • CVE-2018-19985MedMar 21, 2019
    risk 0.30cvss 4.6epss 0.01

    The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel…

  • CVE-2018-14780MedAug 15, 2018
    risk 0.30cvss 4.6epss 0.00

    An out-of-bounds read issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `_ykpiv_fetch_object()`: {% highlight c %} if(sw == SW_SUCCESS) { size_t outlen; int offs = _ykpiv_get_length(data + 1, &outlen);…

  • CVE-2026-20496MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID:…

  • CVE-2026-20490MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.

  • CVE-2026-20489MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID:…

  • CVE-2026-20488MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue…

  • CVE-2026-17572MedJul 27, 2026
    risk 0.29cvss 5.5epss 0.00

    Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max,…