VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 450 of 467
  • CVE-2022-2257HigJun 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2206HigJun 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2183HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-34299HigJun 23, 2022
    risk 0.00cvss 8.1epss 0.01

    There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

  • CVE-2022-2175HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1720HigJun 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

  • CVE-2022-2126HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2124HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1987HigJun 3, 2022
    risk 0.00cvss 8.1epss 0.01

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

  • CVE-2022-32200HigJun 2, 2022
    risk 0.00cvss 7.8epss 0.01

    libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.

  • CVE-2022-31796MedJun 2, 2022
    risk 0.00cvss 6.5epss 0.01

    libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.

  • CVE-2022-31001HigMay 31, 2022
    risk 0.00cvss 7.5epss 0.02

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -…

  • CVE-2022-31002HigMay 31, 2022
    risk 0.00cvss 7.5epss 0.02

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a…

  • CVE-2022-1927HigMay 29, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1908HigMay 27, 2022
    risk 0.00cvss 8.1epss 0.01

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

  • CVE-2022-1907HigMay 27, 2022
    risk 0.00cvss 8.1epss 0.01

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

  • CVE-2022-1899CriMay 26, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

  • CVE-2022-1851HigMay 25, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1769HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

  • CVE-2022-1587CriMay 16, 2022
    risk 0.00cvss 9.1epss 0.03

    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.