VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 407 of 470
  • CVE-2026-1940MedMar 23, 2026
    risk 0.26cvss 5.1epss 0.00

    An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd…

  • CVE-2026-28540MedMar 5, 2026
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-43205MedNov 12, 2025
    risk 0.26cvss 4.0epss 0.00

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bypass ASLR.

  • CVE-2025-21069MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21068MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21067MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21066MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21054MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

  • CVE-2023-35657MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-43265MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.

  • CVE-2025-43226MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of…

  • CVE-2025-52938MedJun 23, 2025
    risk 0.26cvss epss 0.00

    Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: through v0.11. The singlevar() in lparser.c lacks a certain luaK_exp2anyregup call, leading to a…

  • CVE-2025-20992MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.

  • CVE-2025-29839MedMay 13, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

  • CVE-2025-32460MedApr 9, 2025
    risk 0.26cvss 4.0epss 0.00

    GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

  • CVE-2025-32365MedApr 5, 2025
    risk 0.26cvss 4.0epss 0.00

    Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

  • CVE-2025-30347MedMar 21, 2025
    risk 0.26cvss 4.0epss 0.00

    Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

  • CVE-2024-57822MedJan 10, 2025
    risk 0.26cvss 4.0epss 0.00

    In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

  • CVE-2024-47250MedNov 26, 2024
    risk 0.26cvss 5.0epss 0.01

    Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluetooth controller and thus…

  • CVE-2023-39180MedNov 18, 2024
    risk 0.26cvss 4.0epss 0.01

    A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux.…