CWE-823
Use of Out-of-range Pointer Offset
Description
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (101)
page 3 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28564 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. | ||
| CVE-2023-22387 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | ||
| CVE-2016-2161 | Hig | 0.50 | 7.5 | 0.21 | Jul 27, 2017 | In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests. | ||
| CVE-2026-4693 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | ||
| CVE-2025-11232 | Hig | 0.49 | 7.5 | 0.00 | Oct 29, 2025 | To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the… | ||
| CVE-2020-13573 | Hig | 0.49 | 7.5 | 0.03 | Jan 7, 2021 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this… | ||
| CVE-2024-6603 | Hig | 0.48 | 7.4 | 0.01 | Jul 9, 2024 | In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. | ||
| CVE-2021-1352 | Hig | 0.48 | 7.4 | 0.00 | Mar 24, 2021 | A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of… | ||
| CVE-2024-12577 | Hig | 0.47 | 7.3 | 0.00 | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2026-49746 | — | Hig | 0.46 | 7.1 | 0.00 | Aug 7, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of… | |
| CVE-2024-47895 | Hig | 0.46 | 7.1 | 0.00 | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. | ||
| CVE-2024-47894 | Hig | 0.46 | 7.1 | 0.00 | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. | ||
| CVE-2022-42264 | Hig | 0.46 | 7.1 | 0.00 | Dec 30, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service. | ||
| CVE-2025-33215 | Med | 0.44 | 6.8 | 0.00 | Mar 24, 2026 | NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the… | ||
| CVE-2026-23764 | Med | 0.44 | — | 0.00 | Jan 22, 2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a… | ||
| CVE-2024-52937 | Med | 0.44 | 6.7 | 0.00 | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2024-33041 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | ||
| CVE-2024-33036 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | ||
| CVE-2024-23377 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver. | ||
| CVE-2023-33067 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
- risk 0.50cvss 7.5epss 0.21
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
- risk 0.49cvss 7.5epss 0.01
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- risk 0.49cvss 7.5epss 0.00
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the…
- risk 0.49cvss 7.5epss 0.03
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this…
- risk 0.48cvss 7.4epss 0.01
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
- risk 0.48cvss 7.4epss 0.00
A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of…
- risk 0.47cvss 7.3epss 0.00
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.46cvss 7.1epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of…
- risk 0.46cvss 7.1epss 0.00
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
- risk 0.46cvss 7.1epss 0.00
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
- risk 0.46cvss 7.1epss 0.00
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.
- risk 0.44cvss 6.8epss 0.00
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the…
- risk 0.44cvss —epss 0.00
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a…
- risk 0.44cvss 6.7epss 0.00
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.