VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 428 of 467
  • CVE-2023-42119LowMay 3, 2024
    risk 0.20cvss 3.1epss 0.02

    Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2021-25454LowSep 9, 2021
    risk 0.20cvss 3.1epss 0.00

    OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

  • CVE-2021-28801LowJun 11, 2021
    risk 0.20cvss 3.1epss 0.01

    An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read sensitive information on the system. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on…

  • CVE-2016-2380LowJan 6, 2017
    risk 0.20cvss 3.1epss 0.02

    An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and…

  • CVE-2026-47104MedMay 27, 2026
    risk 0.19cvss 4.0epss 0.00

    libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to…

  • CVE-2026-27798MedFeb 26, 2026
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions…

  • CVE-2023-53154LowMay 23, 2025
    risk 0.19cvss 2.9epss 0.00

    parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

  • CVE-2025-48188LowMay 16, 2025
    risk 0.19cvss 2.9epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

  • CVE-2025-47816LowMay 10, 2025
    risk 0.19cvss 2.9epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

  • CVE-2025-32415LowApr 17, 2025
    risk 0.19cvss 2.9epss 0.01

    In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be…

  • CVE-2023-49602LowMar 4, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2023-25176LowMar 4, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2023-49118LowFeb 2, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

  • CVE-2023-43756LowFeb 2, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

  • CVE-2022-23523MedDec 13, 2022
    risk 0.19cvss 4.0epss 0.00

    In versions prior to 0.8.1, the linux-loader crate uses the offsets and sizes provided in the ELF headers to determine the offsets to read from. If those offsets point beyond the end of the file this could lead to Virtual Machine Monitors using the `linux-loader` crate entering…

  • CVE-2022-27831LowApr 11, 2022
    risk 0.19cvss 2.9epss 0.00

    Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

  • CVE-2026-70598LowAug 5, 2026
    risk 0.18cvss 3.9epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised…

  • CVE-2025-66037LowMar 30, 2026
    risk 0.18cvss 3.9epss 0.00

    OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields()…

  • CVE-2026-22717LowFeb 27, 2026
    risk 0.18cvss 2.7epss 0.00

    Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

  • CVE-2025-53051LowOct 21, 2025
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS…