VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,795)

page 474 of 490
  • CVE-2026-56193HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-54996HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54991HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54988MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-54111HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50300MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-49794MedJul 14, 2026
    risk 0.00cvss 4.6epss 0.00

    Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

  • CVE-2026-53566MedJul 14, 2026
    risk 0.00cvss —epss 0.00

    Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.

  • CVE-2026-40454HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5…

  • CVE-2026-58307MedJul 9, 2026
    risk 0.00cvss 6.1epss 0.00

    Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.

  • CVE-2026-58304MedJul 9, 2026
    risk 0.00cvss 6.1epss 0.00

    Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

  • CVE-2026-57258MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.

  • CVE-2026-57257MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.

  • CVE-2026-57255MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing…

  • CVE-2026-57253MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.

  • CVE-2026-57243MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.

  • CVE-2026-57241MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due…

  • CVE-2026-14422HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14420CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-14416CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)