VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 4 of 467
  • CVE-2024-28537CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.

  • CVE-2024-0794CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.

  • CVE-2021-42144CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().

  • CVE-2023-36424HigKEVNov 14, 2023
    risk 0.64cvss 7.8epss 0.12

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-46570CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46569CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-35648CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2023-35647CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2023-37285CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-21130CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-48479CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2023-23301CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends…

  • CVE-2022-31747CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have…

  • CVE-2022-46320CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.00

    The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.

  • CVE-2022-46393CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

  • CVE-2022-20473CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.09

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20472CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.07

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-41580CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2021-0942CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.…

  • CVE-2021-34085CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872.…