VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 385 of 470
  • CVE-2023-21314MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-4156MedSep 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

  • CVE-2023-32817MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: ALPS08044035.

  • CVE-2023-32816MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: ALPS08044032.

  • CVE-2023-32815MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.

  • CVE-2023-32814MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08031947; Issue ID: ALPS08031947.

  • CVE-2023-32810MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.

  • CVE-2023-32807MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360.

  • CVE-2023-20836MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In camsys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505629; Issue ID: ALPS07505629.

  • CVE-2023-20823MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In cmdq, there is a possible out of bounds read due to an incorrect status check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08021592; Issue ID: ALPS08021592.

  • CVE-2022-47352MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-22338MedAug 11, 2023
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-20818MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; Issue ID: ALPS07460540.

  • CVE-2023-20813MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; Issue ID: ALPS07453549.

  • CVE-2023-20798MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.

  • CVE-2022-47351MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2022-47350MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-2860MedJul 24, 2023
    risk 0.29cvss 4.4epss 0.00

    An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an…

  • CVE-2023-33904MedJul 12, 2023
    risk 0.29cvss 4.4epss 0.00

    In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2023-30665MedJul 6, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.