VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 453 of 467
  • CVE-2022-0173MedJan 11, 2022
    risk 0.00cvss 5.5epss 0.01

    radare2 is vulnerable to Out-of-bounds Read

  • CVE-2022-0128HigJan 6, 2022
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-4193MedDec 31, 2021
    risk 0.00cvss 5.5epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-43845HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.04

    PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users…

  • CVE-2021-4166HigDec 25, 2021
    risk 0.00cvss 7.1epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-45469HigDec 23, 2021
    risk 0.00cvss 7.8epss 0.01

    In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

  • CVE-2021-43804HigDec 22, 2021
    risk 0.00cvss 7.3epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not…

  • CVE-2021-4048CriDec 8, 2021
    risk 0.00cvss 9.1epss 0.03

    An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or…

  • CVE-2021-43389MedNov 4, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.

  • CVE-2021-40985MedNov 3, 2021
    risk 0.00cvss 5.5epss 0.01

    A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

  • CVE-2021-22563MedNov 1, 2021
    risk 0.00cvss 4.5epss 0.00

    Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch…

  • CVE-2020-12141CriOct 19, 2021
    risk 0.00cvss 9.1epss 0.02

    An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.

  • CVE-2021-3881CriOct 15, 2021
    risk 0.00cvss 9.8epss 0.01

    libmobi is vulnerable to Out-of-bounds Read

  • CVE-2021-32672MedOct 4, 2021
    risk 0.00cvss 5.3epss 0.02

    Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging…

  • CVE-2021-40812MedSep 8, 2021
    risk 0.00cvss 6.5epss 0.02

    The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks.

  • CVE-2021-40516HigSep 5, 2021
    risk 0.00cvss 7.5epss 0.02

    WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.

  • CVE-2021-37620MedAug 9, 2021
    risk 0.00cvss 4.7epss 0.01

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a…

  • CVE-2021-37619MedAug 9, 2021
    risk 0.00cvss 4.7epss 0.01

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a…

  • CVE-2021-37618MedAug 9, 2021
    risk 0.00cvss 4.7epss 0.01

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a…

  • CVE-2021-38115MedAug 4, 2021
    risk 0.00cvss 6.5epss 0.02

    read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.