VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 431 of 467
  • CVE-2026-2241LowFeb 9, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be…

  • CVE-2026-2240LowFeb 9, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the…

  • CVE-2025-15506LowJan 11, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached…

  • CVE-2025-11000LowSep 26, 2025
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file /src/formats/PQSformat.cpp. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been publicly…

  • CVE-2024-28051LowNov 13, 2024
    risk 0.14cvss 2.2epss 0.00

    Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-11043LowMay 29, 2020
    risk 0.14cvss 2.2epss 0.02

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0.

  • CVE-2020-11040LowMay 29, 2020
    risk 0.14cvss 2.2epss 0.02

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0.

  • CVE-2020-11526LowMay 15, 2020
    risk 0.14cvss 2.2epss 0.02

    libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.

  • CVE-2019-10209LowOct 29, 2019
    risk 0.14cvss 2.2epss 0.01

    Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

  • CVE-2026-10684LowJul 29, 2026
    risk 0.13cvss 3.0epss 0.00

    In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of string pointers, with no bounds check. A stored coredump whose…

  • CVE-2025-53470LowJan 10, 2026
    risk 0.13cvss 3.1epss 0.00

    Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.  This issue requires a broken or bogus Bluetooth controller and thus severity is…

  • CVE-2025-5941LowAug 14, 2025
    risk 0.13cvss epss 0.00

    Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based on the exact…

  • CVE-2023-37377LowSep 8, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, and Exynos W920). Improper handling of length parameter inconsistency can cause incorrect packet filtering.

  • CVE-2020-4033LowJun 22, 2020
    risk 0.13cvss 3.1epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.

  • CVE-2026-61862LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This…

  • CVE-2026-11786LowJun 9, 2026
    risk 0.12cvss 1.9epss 0.00

    A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.

  • CVE-2024-21950LowMay 15, 2026
    risk 0.12cvss epss 0.00

    An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memory outside of established bounds potentially resulting in loss of confidentiality or availability.

  • CVE-2023-53161LowJul 28, 2025
    risk 0.12cvss 2.9epss 0.00

    The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

  • CVE-2023-53160LowJul 28, 2025
    risk 0.12cvss 2.9epss 0.00

    The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.

  • CVE-2021-26345LowNov 14, 2023
    risk 0.12cvss 1.9epss 0.00

    Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.