VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 384 of 470
  • CVE-2024-24826MedFeb 12, 2024
    risk 0.29cvss 5.5epss 0.00

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions…

  • CVE-2024-20820MedFeb 6, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

  • CVE-2023-32880MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.

  • CVE-2023-32878MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.

  • CVE-2023-32876MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.

  • CVE-2023-32875MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.

  • CVE-2023-32857MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS07993710.

  • CVE-2023-32856MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS07993705.

  • CVE-2023-42731MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In Gnss service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42726MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42725MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42724MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42684MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42683MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-42680MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-43574MedNov 8, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

  • CVE-2023-43572MedNov 8, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

  • CVE-2023-21379MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21359MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21357MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.