VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 382 of 470
  • CVE-2025-21018MedAug 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-54637MedAug 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-23286MedAug 2, 2025
    risk 0.29cvss 4.4epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-32776MedApr 15, 2025
    risk 0.29cvss 5.5epss 0.00

    OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attacker can cause the custom kernel driver to read more bytes than provided by user…

  • CVE-2024-11679MedApr 11, 2025
    risk 0.29cvss 4.4epss 0.00

    An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.

  • CVE-2025-20901MedFeb 4, 2025
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2018-9383MedJan 17, 2025
    risk 0.29cvss 4.4epss 0.00

    In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-54114MedDec 12, 2024
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2018-9408MedDec 5, 2024
    risk 0.29cvss 4.4epss 0.00

    In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20116MedDec 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

  • CVE-2024-38654MedNov 13, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

  • CVE-2024-20124MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1568.

  • CVE-2024-20123MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.

  • CVE-2024-20122MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1572.

  • CVE-2024-20117MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1681.

  • CVE-2024-20112MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.

  • CVE-2024-47028MedOct 25, 2024
    risk 0.29cvss 4.4epss 0.00

    In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20097MedOct 7, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1630.

  • CVE-2024-20096MedOct 7, 2024
    risk 0.29cvss 4.4epss 0.00

    In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MSV-1635.

  • CVE-2024-20095MedOct 7, 2024
    risk 0.29cvss 4.4epss 0.00

    In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996894; Issue ID: MSV-1636.