VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 426 of 467
  • CVE-2022-35905LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-35904LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-35903LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a 3DS file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-35902LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an OBJ file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-35901LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a J2K file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-35900LowJul 15, 2022
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a JP2 file containing crafted data can force an out-of-bounds read. Exploitation of these…

  • CVE-2022-25821LowMar 10, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.

  • CVE-2021-44448LowDec 14, 2021
    risk 0.21cvss 3.3epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this…

  • CVE-2021-44436LowDec 14, 2021
    risk 0.21cvss 3.3epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker…

  • CVE-2021-44431LowDec 14, 2021
    risk 0.21cvss 3.3epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker…

  • CVE-2021-22464LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart.

  • CVE-2021-22453LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

  • CVE-2021-38440LowOct 18, 2021
    risk 0.21cvss 3.3epss 0.01

    FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to read unauthorized information.

  • CVE-2021-25455LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.

  • CVE-2021-22365LowJun 22, 2021
    risk 0.21cvss 3.3epss 0.00

    There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful…

  • CVE-2021-3588LowJun 10, 2021
    risk 0.21cvss 3.3epss 0.00

    The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

  • CVE-2021-27260LowApr 14, 2021
    risk 0.21cvss 3.2epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2020-13362LowMay 28, 2020
    risk 0.21cvss 3.2epss 0.00

    In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

  • CVE-2020-5833LowMay 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-2748LowApr 15, 2020
    risk 0.21cvss 3.2epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the…