VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 80 of 470
  • CVE-2025-27733HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-27728HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27490HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27483HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-26675HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26642HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-3288HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3287HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the…

  • CVE-2025-3286HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3285HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-21438HigApr 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while IOCTL call is invoked from user-space to read board data.

  • CVE-2025-21985HigApr 1, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT & HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is necessary to check location…

  • CVE-2025-1659HigApr 1, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-1658HigApr 1, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-24228HigMar 31, 2025
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2025-2231HigMar 24, 2025
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that…

  • CVE-2025-1652HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-1433HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-1431HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-1428HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.