VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 425 of 467
  • CVE-2023-30985LowMay 9, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain an out of bounds read past the end of an allocated buffer while parsing a specially crafted OBJ file. This…

  • CVE-2023-2226LowApr 21, 2023
    risk 0.21cvss 3.3epss 0.00

    Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files.  For this attack to succeed, the attacker needs to be able to introduce malicious…

  • CVE-2023-22846LowApr 20, 2023
    risk 0.21cvss 3.3epss 0.00

    Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.

  • CVE-2023-22354LowApr 20, 2023
    risk 0.21cvss 3.3epss 0.00

    Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.

  • CVE-2023-22321LowApr 20, 2023
    risk 0.21cvss 3.3epss 0.00

    Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.

  • CVE-2023-22295LowApr 20, 2023
    risk 0.21cvss 3.3epss 0.00

    Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.

  • CVE-2023-22808LowApr 11, 2023
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

  • CVE-2023-24565LowFeb 14, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains an out of bounds read past the end of an allocated buffer while parsing a…

  • CVE-2022-2966LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

  • CVE-2022-20528LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-45484LowDec 13, 2022
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.9), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization…

  • CVE-2022-42769LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42758LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42757LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-40709LowSep 28, 2022
    risk 0.21cvss 3.3epss 0.00

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-40708LowSep 28, 2022
    risk 0.21cvss 3.3epss 0.00

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-40707LowSep 28, 2022
    risk 0.21cvss 3.3epss 0.00

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-38934LowSep 28, 2022
    risk 0.21cvss 3.3epss 0.00

    readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.

  • CVE-2022-1404LowAug 31, 2022
    risk 0.21cvss 3.3epss 0.00

    Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

  • CVE-2022-35906LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a DGN file containing crafted data can force an out-of-bounds read. Exploitation of these…