VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 456 of 467
  • CVE-2020-25023CriSep 4, 2020
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.

  • CVE-2020-25022CriSep 4, 2020
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.

  • CVE-2020-25021CriSep 4, 2020
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access.

  • CVE-2020-24977MedSep 4, 2020
    risk 0.00cvss 6.5epss 0.04

    GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

  • CVE-2020-15889CriJul 21, 2020
    risk 0.00cvss 9.8epss 0.02

    Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

  • CVE-2020-15888HigJul 21, 2020
    risk 0.00cvss 8.8epss 0.02

    Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

  • CVE-2020-15476HigJul 1, 2020
    risk 0.00cvss 7.5epss 0.02

    In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

  • CVE-2020-15473CriJul 1, 2020
    risk 0.00cvss 9.1epss 0.01

    In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

  • CVE-2020-15472CriJul 1, 2020
    risk 0.00cvss 9.1epss 0.01

    In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.

  • CVE-2020-15471CriJul 1, 2020
    risk 0.00cvss 9.1epss 0.01

    In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

  • CVE-2020-4030LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

  • CVE-2020-11099LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.

  • CVE-2020-11098LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.

  • CVE-2020-11097LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-11096LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.

  • CVE-2020-11095LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-12886CriJun 18, 2020
    risk 0.00cvss 9.1epss 0.01

    A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses the CoAP packet header starting from the message token. The length of the token in…

  • CVE-2020-12884CriJun 18, 2020
    risk 0.00cvss 9.1epss 0.01

    A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse_multiple_options() parses CoAP options that may occur multiple consecutive times in a single…

  • CVE-2020-12883CriJun 18, 2020
    risk 0.00cvss 9.1epss 0.02

    Buffer over-reads were discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the…

  • CVE-2020-14163HigJun 15, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs did not consider the case where garbage collection is triggered after the key operation but before the value operation, as demonstrated by improper read…