VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 68 of 470
  • CVE-2018-4985HigJul 9, 2018
    risk 0.52cvss 7.5epss 0.31

    Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2018-4956HigJul 9, 2018
    risk 0.52cvss 7.5epss 0.25

    Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2018-4949HigJul 9, 2018
    risk 0.52cvss 7.5epss 0.25

    Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2018-3739CriJun 7, 2018
    risk 0.52cvss 9.1epss 0.02

    https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

  • CVE-2017-13261HigApr 4, 2018
    risk 0.52cvss 7.5epss 0.06

    In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2017-13260HigApr 4, 2018
    risk 0.52cvss 7.5epss 0.06

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2017-13258HigApr 4, 2018
    risk 0.52cvss 7.5epss 0.06

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2026-18716HigAug 20, 2026
    risk 0.51cvss 7.9epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

  • CVE-2026-17124HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.

  • CVE-2026-58087HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer sized for that count, and reacquired the lock. A sequence-number check was used to verify that the set had not been replaced…

  • CVE-2026-68814HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-68793HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-65787HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65786HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-64909HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-63515HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62880HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62876HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62733HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-64629HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to…