VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,795)

page 485 of 490
  • CVE-2022-2581HigAug 1, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.

  • CVE-2022-2469LowJul 19, 2022
    risk 0.00cvss 3.8epss 0.01

    GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

  • CVE-2022-2380MedJul 13, 2022
    risk 0.00cvss 5.5epss 0.00

    The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

  • CVE-2022-2301MedJul 4, 2022
    risk 0.00cvss 5.5epss 0.01

    Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.

  • CVE-2022-2287HigJul 2, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2286HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2257HigJun 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2206HigJun 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2183HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-34299HigJun 23, 2022
    risk 0.00cvss 8.1epss 0.01

    There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

  • CVE-2022-2175HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1720HigJun 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

  • CVE-2022-2126HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2124HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1987HigJun 3, 2022
    risk 0.00cvss 8.1epss 0.01

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

  • CVE-2022-32200HigJun 2, 2022
    risk 0.00cvss 7.8epss 0.01

    libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.

  • CVE-2022-31796MedJun 2, 2022
    risk 0.00cvss 6.5epss 0.01

    libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.

  • CVE-2022-31001HigMay 31, 2022
    risk 0.00cvss 7.5epss 0.02

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) -…

  • CVE-2022-31002HigMay 31, 2022
    risk 0.00cvss 7.5epss 0.02

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a…

  • CVE-2022-1927HigMay 29, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.