VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 452 of 467
  • CVE-2021-32434MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.01

    abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.

  • CVE-2021-3743HigMar 4, 2022
    risk 0.00cvss 7.1epss 0.01

    An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest…

  • CVE-2021-45864MedMar 2, 2022
    risk 0.00cvss 5.5epss 0.01

    tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.

  • CVE-2021-3610HigFeb 24, 2022
    risk 0.00cvss 7.5epss 0.03

    A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

  • CVE-2022-0717CriFeb 23, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-0630HigFeb 19, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-23645MedFeb 18, 2022
    risk 0.00cvss 6.2epss 0.00

    swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid…

  • CVE-2022-0623CriFeb 17, 2022
    risk 0.00cvss 9.1epss 0.02

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2021-3753MedFeb 16, 2022
    risk 0.00cvss 4.7epss 0.00

    A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data…

  • CVE-2022-0534MedFeb 9, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

  • CVE-2022-0525CriFeb 9, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-24198MedFeb 1, 2022
    risk 0.00cvss 6.5epss 0.01

    iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be…

  • CVE-2021-41040HigFeb 1, 2022
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

  • CVE-2022-0393HigJan 28, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21723CriJan 27, 2022
    risk 0.00cvss 9.1epss 0.04

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can…

  • CVE-2022-21722CriJan 27, 2022
    risk 0.00cvss 9.1epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP…

  • CVE-2022-0368HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21711HigJan 24, 2022
    risk 0.00cvss 7.1epss 0.01

    elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…

  • CVE-2022-0319MedJan 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Out-of-bounds Read in vim/vim prior to 8.2.

  • CVE-2020-19860MedJan 21, 2022
    risk 0.00cvss 6.5epss 0.01

    When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.