CWE-823
Use of Out-of-range Pointer Offset
Description
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (101)
page 1 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33106 | Hig | 0.67 | 8.4 | 0.01 | KEV | Dec 5, 2023 | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | |
| CVE-2017-11076 | Cri | 0.64 | 9.8 | 0.00 | Nov 26, 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. | ||
| CVE-2023-43553 | Cri | 0.64 | 9.8 | 0.00 | Mar 4, 2024 | Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE. | ||
| CVE-2023-22388 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | ||
| CVE-2023-24855 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Memory corruption in Modem while processing security related configuration before AS Security Exchange. | ||
| CVE-2026-21732 | Cri | 0.62 | 9.6 | 0.00 | Mar 20, 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits… | ||
| CVE-2025-27059 | Hig | 0.57 | 8.8 | 0.00 | Oct 9, 2025 | Memory corruption while performing SCM call. | ||
| CVE-2024-42416 | Hig | 0.57 | 8.8 | 0.00 | Sep 5, 2024 | The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to… | ||
| CVE-2017-20211 | Hig | 0.56 | — | 0.01 | Nov 12, 2025 | UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A… | ||
| CVE-2023-43534 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | ||
| CVE-2023-20187 | Hig | 0.56 | 8.6 | 0.01 | Sep 27, 2023 | A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS)… | ||
| CVE-2023-33066 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. | ||
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2022-25709 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to use of out of range pointer offset while processing qmi msg | ||
| CVE-2022-25694 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | ||
| CVE-2026-12290 | Hig | 0.53 | 8.1 | 0.00 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | ||
| CVE-2025-0467 | Hig | 0.53 | 8.2 | 0.00 | Apr 18, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2024-42386 | Hig | 0.53 | 8.2 | 0.00 | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. | ||
| CVE-2022-32142 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2022 | Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which… | ||
| CVE-2021-34595 | Hig | 0.53 | 8.1 | 0.01 | Oct 26, 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. |
- risk 0.67cvss 8.4epss 0.01
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- risk 0.64cvss 9.8epss 0.00
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
- risk 0.64cvss 9.8epss 0.00
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
- risk 0.64cvss 9.8epss 0.00
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- risk 0.62cvss 9.6epss 0.00
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits…
- risk 0.57cvss 8.8epss 0.00
Memory corruption while performing SCM call.
- risk 0.57cvss 8.8epss 0.00
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to…
- risk 0.56cvss —epss 0.01
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A…
- risk 0.56cvss 8.6epss 0.00
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- risk 0.56cvss 8.6epss 0.01
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS)…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while processing RT proxy port register driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- risk 0.53cvss 8.1epss 0.00
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- risk 0.53cvss 8.2epss 0.00
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.53cvss 8.2epss 0.00
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
- risk 0.53cvss 8.1epss 0.01
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which…
- risk 0.53cvss 8.1epss 0.01
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.