VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 396 of 470
  • CVE-2019-18849MedNov 11, 2019
    risk 0.29cvss 5.5epss 0.01

    In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • CVE-2019-17138MedOct 25, 2019
    risk 0.29cvss 4.3epss 0.08

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2019-9360MedSep 27, 2019
    risk 0.29cvss 4.4epss 0.00

    In the TEE, there's a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120610663

  • CVE-2019-9452MedSep 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In the Android kernel in SEC_TS touch driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9449MedSep 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In the Android kernel in FingerTipS touchscreen driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9445MedSep 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9245MedSep 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In the Android kernel in the f2fs driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2015-9289MedJul 27, 2019
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.

  • CVE-2019-0116MedMay 17, 2019
    risk 0.29cvss 4.4epss 0.00

    An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2016-7151MedMay 15, 2019
    risk 0.29cvss 5.5epss 0.01

    Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.

  • CVE-2019-3812MedFeb 19, 2019
    risk 0.29cvss 4.4epss 0.00

    QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the…

  • CVE-2019-8905MedFeb 18, 2019
    risk 0.29cvss 4.4epss 0.00

    do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

  • CVE-2018-15378MedOct 15, 2018
    risk 0.29cvss 5.5epss 0.02

    A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an…

  • CVE-2018-16982MedSep 13, 2018
    risk 0.29cvss 5.5epss 0.02

    Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset values via a crafted .ocd file.

  • CVE-2018-16062MedAug 29, 2018
    risk 0.29cvss 5.5epss 0.02

    dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

  • CVE-2018-14851MedAug 2, 2018
    risk 0.29cvss 5.5epss 0.08

    exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.

  • CVE-2016-9583MedAug 1, 2018
    risk 0.29cvss 5.5epss 0.02

    An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

  • CVE-2018-14017MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted .class file because of missing input validation in…

  • CVE-2018-14016MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.

  • CVE-2017-15814MedMar 16, 2018
    risk 0.29cvss 4.4epss 0.00

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in msm_flash_subdev_do_ioctl of drivers/media/platform/msm/camera_v2/sensor/flash/msm_flash.c, there is a possible out of bounds read if flash_data.cfg_type is…