CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,337)
page 452 of 467| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32434 | Med | 0.00 | 5.5 | 0.01 | Mar 10, 2022 | abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c. | ||
| CVE-2021-3743 | Hig | 0.00 | 7.1 | 0.01 | Mar 4, 2022 | An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest… | ||
| CVE-2021-45864 | Med | 0.00 | 5.5 | 0.01 | Mar 2, 2022 | tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp. | ||
| CVE-2021-3610 | Hig | 0.00 | 7.5 | 0.03 | Feb 24, 2022 | A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault. | ||
| CVE-2022-0717 | Cri | 0.00 | 9.1 | 0.01 | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-0630 | Hig | 0.00 | 7.1 | 0.01 | Feb 19, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2022-23645 | Med | 0.00 | 6.2 | 0.00 | Feb 18, 2022 | swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid… | ||
| CVE-2022-0623 | Cri | 0.00 | 9.1 | 0.02 | Feb 17, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2021-3753 | Med | 0.00 | 4.7 | 0.00 | Feb 16, 2022 | A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data… | ||
| CVE-2022-0534 | Med | 0.00 | 5.5 | 0.01 | Feb 9, 2022 | A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault). | ||
| CVE-2022-0525 | Cri | 0.00 | 9.1 | 0.01 | Feb 9, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2022-24198 | Med | 0.00 | 6.5 | 0.01 | Feb 1, 2022 | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be… | ||
| CVE-2021-41040 | Hig | 0.00 | 7.5 | 0.01 | Feb 1, 2022 | In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data. | ||
| CVE-2022-0393 | Hig | 0.00 | 7.1 | 0.01 | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-21723 | Cri | 0.00 | 9.1 | 0.04 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can… | ||
| CVE-2022-21722 | Cri | 0.00 | 9.1 | 0.02 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP… | ||
| CVE-2022-0368 | Hig | 0.00 | 7.8 | 0.02 | Jan 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-21711 | Hig | 0.00 | 7.1 | 0.01 | Jan 24, 2022 | elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By… | ||
| CVE-2022-0319 | Med | 0.00 | 5.5 | 0.01 | Jan 21, 2022 | Out-of-bounds Read in vim/vim prior to 8.2. | ||
| CVE-2020-19860 | Med | 0.00 | 6.5 | 0.01 | Jan 21, 2022 | When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload. |
- risk 0.00cvss 5.5epss 0.01
abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.
- risk 0.00cvss 7.1epss 0.01
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest…
- risk 0.00cvss 5.5epss 0.01
tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.
- risk 0.00cvss 7.5epss 0.03
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 6.2epss 0.00
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid…
- risk 0.00cvss 9.1epss 0.02
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 4.7epss 0.00
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data…
- risk 0.00cvss 5.5epss 0.01
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 6.5epss 0.01
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be…
- risk 0.00cvss 7.5epss 0.01
In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 9.1epss 0.04
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can…
- risk 0.00cvss 9.1epss 0.02
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP…
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.1epss 0.01
elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds Read in vim/vim prior to 8.2.
- risk 0.00cvss 6.5epss 0.01
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.