VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 79 of 470
  • CVE-2025-47753HigMay 19, 2025
    risk 0.51cvss 7.8epss 0.00

    V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

  • CVE-2025-30420HigMay 15, 2025
    risk 0.51cvss 7.8epss 0.00

    There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an…

  • CVE-2025-30419HigMay 15, 2025
    risk 0.51cvss 7.8epss 0.00

    There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an…

  • CVE-2025-32707HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-32705HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

  • CVE-2025-30381HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30376HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-32454HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualization V2312 (All versions < V2312.0010), Teamcenter Visualization V2406 (All versions < V2406.0008), Teamcenter Visualization V2412 (All versions < V2412.0004),…

  • CVE-2020-36791HigMay 7, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_perfect_hash(), but…

  • CVE-2025-21475HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.

  • CVE-2025-2509HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in…

  • CVE-2023-53090HigMay 2, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix an illegal memory access In the kfd_wait_on_events() function, the kfd_event_waiter structure is allocated by alloc_event_waiters(), but the event field of the waiter structure is not…

  • CVE-2023-53057HigMay 2, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix global-out-of-bounds To loop a variable-length array, hci_init_stage_sync(stage) considers that stage[i] is valid as long as stage[i-1].func is valid. Thus, the last element of stage[].func…

  • CVE-2025-37761HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix an out-of-bounds shift when invalidating TLB When the size of the range invalidated is larger than rounddown_pow_of_two(ULONG_MAX), The function macro roundup_pow_of_two(length) will hit an…

  • CVE-2025-23157HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count…

  • CVE-2025-23156HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: refactor hfi packet parsing logic words_count denotes the number of words in total payload, while data points to payload of various property within it. When words_count reaches last…

  • CVE-2025-22087HigApr 16, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix array bounds error with may_goto may_goto uses an additional 8 bytes on the stack, which causes the interpreters[] array to go out of bounds when calculating index by stack_size. 1. If a BPF program…

  • CVE-2025-22079HigApr 16, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate l_tree_depth to avoid out-of-bounds access The l_tree_depth field is 16-bit (__le16), but the actual maximum depth is limited to OCFS2_MAX_PATH_DEPTH. Add a check to prevent out-of-bounds…

  • CVE-2025-29811HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27741HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.