VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 8 of 467
  • CVE-2019-15505CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.08

    drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).

  • CVE-2019-14531CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.

  • CVE-2015-9290CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.03

    In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.

  • CVE-2019-2307CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2019-2305CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bound access when reason code is extracted from frame data without validating the frame length in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150,…

  • CVE-2019-2276CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music…

  • CVE-2019-2253CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Buffer over-read can occur while parsing an ogg file with a corrupted comment block. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150,…

  • CVE-2019-13962CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.04

    lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

  • CVE-2019-1010295CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.02

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2019-13470CriJul 9, 2019
    risk 0.64cvss 9.8epss 0.02

    MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

  • CVE-2019-13067CriJun 30, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

  • CVE-2018-6350CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to…

  • CVE-2018-13911CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150,…

  • CVE-2018-11955CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.01

    Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame and results in out of bound read in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2018-11953CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.01

    While processing ssid IE length from remote AP, possible out-of-bounds access may occur due to crafted ssid IE length in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2018-11937CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.01

    Lack of input validation before copying can lead to a buffer over read in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, QCS605, SD…

  • CVE-2019-12207CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.

  • CVE-2019-10053CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

  • CVE-2019-11835CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

  • CVE-2019-11834CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.