CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,337)
page 450 of 467| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2257 | Hig | 0.00 | 7.8 | 0.01 | Jun 30, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2206 | Hig | 0.00 | 7.8 | 0.01 | Jun 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2183 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-34299 | Hig | 0.00 | 8.1 | 0.01 | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. | ||
| CVE-2022-2175 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1720 | Hig | 0.00 | 7.8 | 0.02 | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||
| CVE-2022-2126 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2124 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1987 | Hig | 0.00 | 8.1 | 0.01 | Jun 3, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | ||
| CVE-2022-32200 | Hig | 0.00 | 7.8 | 0.01 | Jun 2, 2022 | libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. | ||
| CVE-2022-31796 | Med | 0.00 | 6.5 | 0.01 | Jun 2, 2022 | libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use. | ||
| CVE-2022-31001 | Hig | 0.00 | 7.5 | 0.02 | May 31, 2022 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -… | ||
| CVE-2022-31002 | Hig | 0.00 | 7.5 | 0.02 | May 31, 2022 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a… | ||
| CVE-2022-1927 | Hig | 0.00 | 7.8 | 0.02 | May 29, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1908 | Hig | 0.00 | 8.1 | 0.01 | May 27, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | ||
| CVE-2022-1907 | Hig | 0.00 | 8.1 | 0.01 | May 27, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | ||
| CVE-2022-1899 | Cri | 0.00 | 9.1 | 0.01 | May 26, 2022 | Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. | ||
| CVE-2022-1851 | Hig | 0.00 | 7.8 | 0.02 | May 25, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1769 | Hig | 0.00 | 7.8 | 0.00 | May 17, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. | ||
| CVE-2022-1587 | Cri | 0.00 | 9.1 | 0.03 | May 16, 2022 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. |
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.1epss 0.01
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
- risk 0.00cvss 7.8epss 0.01
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.1epss 0.01
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- risk 0.00cvss 7.8epss 0.01
libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
- risk 0.00cvss 6.5epss 0.01
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
- risk 0.00cvss 7.5epss 0.02
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -…
- risk 0.00cvss 7.5epss 0.02
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a…
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.1epss 0.01
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- risk 0.00cvss 8.1epss 0.01
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
- risk 0.00cvss 9.1epss 0.03
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.