VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,383)

page 97 of 470
  • CVE-2023-29167HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound reads vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.

  • CVE-2023-33123HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization…

  • CVE-2023-31278HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.

  • CVE-2023-27916HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current…

  • CVE-2023-32289HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current…

  • CVE-2023-32281HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the…

  • CVE-2023-32545HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context…

  • CVE-2023-25008HigMay 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.

  • CVE-2023-29281HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in…

  • CVE-2023-29280HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in…

  • CVE-2023-29275HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in…

  • CVE-2023-29274HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in…

  • CVE-2023-29273HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in…

  • CVE-2023-24902HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.05

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-29461HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.01

    An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap. …

  • CVE-2023-29460HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.01

    An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow potentially resulting in a…

  • CVE-2023-27949HigMay 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2023-27946HigMay 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code…

  • CVE-2023-27938HigMay 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in GarageBand for macOS 10.4.8. Parsing a maliciously crafted MIDI file may lead to an unexpected application termination or arbitrary code execution.

  • CVE-2023-2176HigApr 20, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper cleanup results in out-of-boundary read, where a local user can utilize this problem to crash the system or escalation of privilege.