VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 439 of 467
  • CVE-2026-14388MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14386MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14384MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-44041MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp:204, the vncWc2Mb() function passes a caller-supplied WCHAR pointer to wcslen() before any bounds check. If the caller provides a wide-character buffer that…

  • CVE-2026-9263MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per the Bluetooth specification a start segment (sc=0) always carries a 3-byte time_offset, so its…

  • CVE-2026-10817HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

  • CVE-2026-43703MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected…

  • CVE-2026-9267MedJun 29, 2026
    risk 0.00cvss epss 0.00

    Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate…

  • CVE-2026-13522MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in…

  • CVE-2026-45258HigJun 27, 2026
    risk 0.00cvss 7.8epss 0.00

    dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. The offset was then narrowed from 64 to 32…

  • CVE-2026-48770MedJun 26, 2026
    risk 0.00cvss 5.0epss 0.00

    Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to process COPYDATASTRUCT.lpData as…

  • CVE-2026-54341HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, crashing the entire server process (SIGSEGV). Because DragonflyDB requires no…

  • CVE-2026-4526MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47154MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the…

  • CVE-2026-47149MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47148MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the…

  • CVE-2026-47147HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…

  • CVE-2026-55093Jun 18, 2026
    risk 0.00cvss epss

    - **Component:** `tract-nnef` (`nnef/src/tensors.rs::read_tensor`) + `tract-data` (`data/src/tensor.rs`) - **Affected versions:** `< 0.21.16`, `0.22.0`–`0.22.2`, `0.23.0`–`0.23.1` — the dense `DatLoader` path was unguarded across all three release lines; patched in 0.21.16…

  • CVE-2026-7936May 6, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: Determined not a vulnerability

  • CVE-2026-33817Apr 6, 2026
    risk 0.00cvss epss

    Rejected reason: CVE confirmed to be a false positive