VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (529)

page 27 of 27
  • CVE-2021-22563MedNov 1, 2021
    risk 0.00cvss 4.5epss 0.00

    Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch…

  • CVE-2021-22552MedAug 2, 2021
    risk 0.00cvss 5.3epss 0.00

    An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the secure enclave. We…

  • CVE-2019-3563CriApr 29, 2019
    risk 0.00cvss 9.8epss 0.02

    Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00

  • CVE-2018-8799HigFeb 5, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

  • CVE-2018-8798HigFeb 5, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.

  • CVE-2018-8796HigFeb 5, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).

  • CVE-2018-8792HigFeb 5, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).

  • CVE-2018-8791HigFeb 5, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.

  • CVE-2018-8789HigNov 29, 2018
    risk 0.00cvss 7.5epss 0.05

    FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).