VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 94 of 470
  • CVE-2023-26368HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InCopy versions 18.5 (and earlier) and 17.4.2 (and earlier) are affected by are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this…

  • CVE-2023-47043HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to…

  • CVE-2023-47040HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to…

  • CVE-2023-44338HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this…

  • CVE-2023-44337HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this…

  • CVE-2023-47585HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

  • CVE-2023-47583HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially crafted file (X1 or V9 file), information may be disclosed and/or arbitrary code may be executed.

  • CVE-2023-47581HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

  • CVE-2023-5179HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash,…

  • CVE-2023-21372HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-27854HigOct 27, 2023
    risk 0.51cvss 7.8epss 0.00

    An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow.  The threat-actor could then execute…

  • CVE-2023-39936HigOct 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current…

  • CVE-2023-5059HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2023-42138HigOct 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially…

  • CVE-2023-36701HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability

  • CVE-2023-44087HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing…

  • CVE-2023-44086HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing…

  • CVE-2023-44085HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing…

  • CVE-2023-44084HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing…

  • CVE-2023-36766HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Information Disclosure Vulnerability