VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 400 of 470
  • CVE-2025-43445MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing a maliciously…

  • CVE-2025-43421MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43385MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to…

  • CVE-2025-43384MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to…

  • CVE-2025-43383MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to…

  • CVE-2025-21055MedOct 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-40578MedMay 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple…

  • CVE-2025-40577MedMay 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet,…

  • CVE-2025-31354MedApr 11, 2025
    risk 0.28cvss 4.3epss 0.00

    Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters.

  • CVE-2025-3406MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header Array Handler. The manipulation of the argument w leads to out-of-bounds read. It is possible to launch…

  • CVE-2025-2752MedMar 25, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The…

  • CVE-2025-2751MedMar 25, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of…

  • CVE-2025-24055MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.01

    Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.

  • CVE-2025-20640MedFeb 3, 2025
    risk 0.28cvss 4.3epss 0.00

    In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:…

  • CVE-2025-21530MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-54116MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-54115MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-49103MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.01

    Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

  • CVE-2024-49099MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.01

    Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

  • CVE-2024-49098MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.01

    Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability