VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,795)

page 487 of 490
  • CVE-2022-1276CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.02

    Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-28805CriApr 8, 2022
    risk 0.00cvss 9.1epss 0.03

    singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

  • CVE-2022-24786CriApr 6, 2022
    risk 0.00cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A…

  • CVE-2022-1207MedApr 1, 2022
    risk 0.00cvss 6.6epss 0.01

    Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.

  • CVE-2022-0717CriFeb 23, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-0630HigFeb 19, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-23645MedFeb 18, 2022
    risk 0.00cvss 6.2epss 0.00

    swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid…

  • CVE-2022-0623CriFeb 17, 2022
    risk 0.00cvss 9.1epss 0.02

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-0534MedFeb 9, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

  • CVE-2022-0525CriFeb 9, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-24198MedFeb 1, 2022
    risk 0.00cvss 6.5epss 0.01

    iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be…

  • CVE-2022-0393HigJan 28, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21723CriJan 27, 2022
    risk 0.00cvss 9.1epss 0.04

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can…

  • CVE-2022-21722CriJan 27, 2022
    risk 0.00cvss 9.1epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP…

  • CVE-2022-0368HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21711HigJan 24, 2022
    risk 0.00cvss 7.1epss 0.01

    elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…

  • CVE-2022-0319MedJan 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Out-of-bounds Read in vim/vim prior to 8.2.

  • CVE-2022-0173MedJan 11, 2022
    risk 0.00cvss 5.5epss 0.01

    radare2 is vulnerable to Out-of-bounds Read

  • CVE-2022-0128HigJan 6, 2022
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2015-2697Nov 9, 2015
    risk 0.00cvss —epss 0.04

    The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.