CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,795)
page 485 of 490| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2581 | Hig | 0.00 | 7.8 | 0.01 | Aug 1, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104. | ||
| CVE-2022-2469 | Low | 0.00 | 3.8 | 0.01 | Jul 19, 2022 | GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client | ||
| CVE-2022-2380 | Med | 0.00 | 5.5 | 0.00 | Jul 13, 2022 | The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel. | ||
| CVE-2022-2301 | Med | 0.00 | 5.5 | 0.01 | Jul 4, 2022 | Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. | ||
| CVE-2022-2287 | Hig | 0.00 | 7.1 | 0.01 | Jul 2, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2286 | Hig | 0.00 | 7.8 | 0.01 | Jul 2, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2257 | Hig | 0.00 | 7.8 | 0.01 | Jun 30, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2206 | Hig | 0.00 | 7.8 | 0.01 | Jun 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2183 | Hig | 0.00 | 7.8 | 0.02 | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-34299 | Hig | 0.00 | 8.1 | 0.01 | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. | ||
| CVE-2022-2175 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1720 | Hig | 0.00 | 7.8 | 0.02 | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||
| CVE-2022-2126 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2124 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1987 | Hig | 0.00 | 8.1 | 0.01 | Jun 3, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | ||
| CVE-2022-32200 | Hig | 0.00 | 7.8 | 0.01 | Jun 2, 2022 | libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. | ||
| CVE-2022-31796 | Med | 0.00 | 6.5 | 0.01 | Jun 2, 2022 | libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use. | ||
| CVE-2022-31001 | Hig | 0.00 | 7.5 | 0.02 | May 31, 2022 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -… | ||
| CVE-2022-31002 | Hig | 0.00 | 7.5 | 0.02 | May 31, 2022 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a… | ||
| CVE-2022-1927 | Hig | 0.00 | 7.8 | 0.02 | May 29, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. |
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
- risk 0.00cvss 3.8epss 0.01
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
- risk 0.00cvss 5.5epss 0.00
The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.
- risk 0.00cvss 5.5epss 0.01
Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.1epss 0.01
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
- risk 0.00cvss 7.8epss 0.01
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.1epss 0.01
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- risk 0.00cvss 7.8epss 0.01
libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
- risk 0.00cvss 6.5epss 0.01
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
- risk 0.00cvss 7.5epss 0.02
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -…
- risk 0.00cvss 7.5epss 0.02
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a…
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.