VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 387 of 470
  • CVE-2023-21154MedJun 28, 2023
    risk 0.29cvss 4.4epss 0.00

    In StoreAdbSerialNumber of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21150MedJun 28, 2023
    risk 0.29cvss 4.4epss 0.00

    In handle_set_parameters_ctrl of hal_socket.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21148MedJun 28, 2023
    risk 0.29cvss 4.4epss 0.00

    In BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20742MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: ALPS07628540.

  • CVE-2023-20741MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: ALPS07628606.

  • CVE-2023-20731MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573495; Issue ID: ALPS07573495.

  • CVE-2023-20730MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: ALPS07573552.

  • CVE-2023-20729MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: ALPS07573575.

  • CVE-2023-20728MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573603; Issue ID: ALPS07573603.

  • CVE-2023-20727MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588531; Issue ID: ALPS07588531.

  • CVE-2023-20719MedMay 15, 2023
    risk 0.29cvss 4.4epss 0.00

    In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629583; Issue ID: ALPS07629583.

  • CVE-2023-20711MedMay 15, 2023
    risk 0.29cvss 4.4epss 0.00

    In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07581668; Issue ID: ALPS07581668.

  • CVE-2023-20698MedMay 15, 2023
    risk 0.29cvss 4.4epss 0.00

    In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589144; Issue ID: ALPS07589144.

  • CVE-2023-20697MedMay 15, 2023
    risk 0.29cvss 4.4epss 0.00

    In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589148; Issue ID: ALPS07589148.

  • CVE-2022-48236MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In MP3 encoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-47334MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In phasecheck server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-39089MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In mlog service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2023-21511MedMay 4, 2023
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.

  • CVE-2023-21510MedMay 4, 2023
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.

  • CVE-2023-21507MedMay 4, 2023
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.