VYPR

CWE-823

Use of Out-of-range Pointer Offset

BaseIncomplete

Description

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (105)

page 5 of 6
  • CVE-2026-31912MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter…

  • CVE-2024-52936MedJan 13, 2025
    risk 0.29cvss 4.4epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2026-34193MedJun 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to…

  • CVE-2024-42390MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2024-52935MedJan 13, 2025
    risk 0.27cvss 4.1epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2024-42383MedNov 18, 2024
    risk 0.27cvss 4.2epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

  • CVE-2024-47896LowFeb 22, 2025
    risk 0.21cvss 3.3epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2024-42391MedNov 18, 2024
    risk 0.21cvss 4.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2026-21734HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.00

    A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits…

  • CVE-2026-21487MedJan 6, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in…

  • CVE-2024-1013HigMar 18, 2024
    risk 0.00cvss 7.8epss 0.00

    An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.

  • CVE-2023-46724HigNov 1, 2023
    risk 0.00cvss 8.6epss 0.04

    Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem…

  • CVE-2022-46378MedMay 10, 2023
    risk 0.00cvss 6.5epss 0.01

    An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This…

  • CVE-2022-46377MedMay 10, 2023
    risk 0.00cvss 6.5epss 0.01

    An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This…

  • CVE-2023-2426MedApr 29, 2023
    risk 0.00cvss 5.5epss 0.00

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

  • CVE-2022-1420MedApr 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.

  • CVE-2022-0729HigFeb 23, 2022
    risk 0.00cvss 8.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

  • CVE-2022-0685HigFeb 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

  • CVE-2022-0614MedFeb 16, 2022
    risk 0.00cvss 5.5epss 0.01

    Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

  • CVE-2022-0554HigFeb 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.