CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,795)
page 487 of 490| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1276 | Cri | 0.00 | 9.8 | 0.02 | Apr 10, 2022 | Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | ||
| CVE-2022-28805 | Cri | 0.00 | 9.1 | 0.03 | Apr 8, 2022 | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code. | ||
| CVE-2022-24786 | Cri | 0.00 | 9.8 | 0.02 | Apr 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A… | ||
| CVE-2022-1207 | Med | 0.00 | 6.6 | 0.01 | Apr 1, 2022 | Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary. | ||
| CVE-2022-0717 | Cri | 0.00 | 9.1 | 0.01 | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-0630 | Hig | 0.00 | 7.1 | 0.01 | Feb 19, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2022-23645 | Med | 0.00 | 6.2 | 0.00 | Feb 18, 2022 | swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid… | ||
| CVE-2022-0623 | Cri | 0.00 | 9.1 | 0.02 | Feb 17, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2022-0534 | Med | 0.00 | 5.5 | 0.01 | Feb 9, 2022 | A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault). | ||
| CVE-2022-0525 | Cri | 0.00 | 9.1 | 0.01 | Feb 9, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | ||
| CVE-2022-24198 | Med | 0.00 | 6.5 | 0.01 | Feb 1, 2022 | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be… | ||
| CVE-2022-0393 | Hig | 0.00 | 7.1 | 0.01 | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-21723 | Cri | 0.00 | 9.1 | 0.04 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can… | ||
| CVE-2022-21722 | Cri | 0.00 | 9.1 | 0.02 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP… | ||
| CVE-2022-0368 | Hig | 0.00 | 7.8 | 0.02 | Jan 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-21711 | Hig | 0.00 | 7.1 | 0.01 | Jan 24, 2022 | elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By… | ||
| CVE-2022-0319 | Med | 0.00 | 5.5 | 0.01 | Jan 21, 2022 | Out-of-bounds Read in vim/vim prior to 8.2. | ||
| CVE-2022-0173 | Med | 0.00 | 5.5 | 0.01 | Jan 11, 2022 | radare2 is vulnerable to Out-of-bounds Read | ||
| CVE-2022-0128 | Hig | 0.00 | 7.8 | 0.02 | Jan 6, 2022 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2015-2697 | 0.00 | — | 0.04 | Nov 9, 2015 | The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request. |
- risk 0.00cvss 9.8epss 0.02
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- risk 0.00cvss 9.1epss 0.03
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- risk 0.00cvss 9.8epss 0.02
PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A…
- risk 0.00cvss 6.6epss 0.01
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 6.2epss 0.00
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid…
- risk 0.00cvss 9.1epss 0.02
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 5.5epss 0.01
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in Homebrew mruby prior to 3.2.
- risk 0.00cvss 6.5epss 0.01
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be…
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 9.1epss 0.04
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can…
- risk 0.00cvss 9.1epss 0.02
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP…
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.1epss 0.01
elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds Read in vim/vim prior to 8.2.
- risk 0.00cvss 5.5epss 0.01
radare2 is vulnerable to Out-of-bounds Read
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Out-of-bounds Read
- CVE-2015-2697Nov 9, 2015risk 0.00cvss —epss 0.04
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.