VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 408 of 470
  • CVE-2023-4458MedNov 14, 2024
    risk 0.26cvss 4.0epss 0.01

    A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive…

  • CVE-2024-20505MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.01

    A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote…

  • CVE-2024-34658MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

  • CVE-2024-34635MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34634MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34633MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34632MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-23912MedMay 3, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.

  • CVE-2024-20814MedFeb 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

  • CVE-2023-39197MedJan 23, 2024
    risk 0.26cvss 4.0epss 0.01

    An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.

  • CVE-2023-20838MedSep 4, 2023
    risk 0.26cvss 4.0epss 0.00

    In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418.

  • CVE-2022-36854MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

  • CVE-2022-28788MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28787MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28786MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28785MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-27832MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

  • CVE-2022-27825MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

  • CVE-2022-27824MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

  • CVE-2022-27823MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.