CWE-823
Use of Out-of-range Pointer Offset
Description
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (105)
page 5 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-31912 | Med | 0.29 | 5.5 | 0.00 | Sep 5, 2026 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter… | ||
| CVE-2024-52936 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2026-34193 | Med | 0.28 | 4.3 | 0.00 | Jun 1, 2026 | Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to… | ||
| CVE-2024-42390 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | ||
| CVE-2024-52935 | Med | 0.27 | 4.1 | 0.00 | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2024-42383 | Med | 0.27 | 4.2 | 0.00 | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. | ||
| CVE-2024-47896 | Low | 0.21 | 3.3 | 0.00 | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||
| CVE-2024-42391 | Med | 0.21 | 4.3 | 0.00 | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | ||
| CVE-2026-21734 | Hig | 0.00 | 7.7 | 0.00 | Jun 26, 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits… | ||
| CVE-2026-21487 | Med | 0.00 | 6.1 | 0.00 | Jan 6, 2026 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in… | ||
| CVE-2024-1013 | Hig | 0.00 | 7.8 | 0.00 | Mar 18, 2024 | An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken. | ||
| CVE-2023-46724 | Hig | 0.00 | 8.6 | 0.04 | Nov 1, 2023 | Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem… | ||
| CVE-2022-46378 | Med | 0.00 | 6.5 | 0.01 | May 10, 2023 | An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This… | ||
| CVE-2022-46377 | Med | 0.00 | 6.5 | 0.01 | May 10, 2023 | An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This… | ||
| CVE-2023-2426 | Med | 0.00 | 5.5 | 0.00 | Apr 29, 2023 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. | ||
| CVE-2022-1420 | Med | 0.00 | 5.5 | 0.01 | Apr 21, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. | ||
| CVE-2022-0729 | Hig | 0.00 | 8.8 | 0.02 | Feb 23, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. | ||
| CVE-2022-0685 | Hig | 0.00 | 7.8 | 0.02 | Feb 20, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. | ||
| CVE-2022-0614 | Med | 0.00 | 5.5 | 0.01 | Feb 16, 2022 | Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2. | ||
| CVE-2022-0554 | Hig | 0.00 | 7.8 | 0.02 | Feb 10, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. |
- risk 0.29cvss 5.5epss 0.00
libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter…
- risk 0.29cvss 4.4epss 0.00
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.28cvss 4.3epss 0.00
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to…
- risk 0.28cvss 4.3epss 0.00
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
- risk 0.27cvss 4.1epss 0.00
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.27cvss 4.2epss 0.00
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
- risk 0.21cvss 3.3epss 0.00
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- risk 0.21cvss 4.3epss 0.00
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
- risk 0.00cvss 7.7epss 0.00
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits…
- risk 0.00cvss 6.1epss 0.00
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in…
- risk 0.00cvss 7.8epss 0.00
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.
- risk 0.00cvss 8.6epss 0.04
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem…
- risk 0.00cvss 6.5epss 0.01
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This…
- risk 0.00cvss 6.5epss 0.01
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This…
- risk 0.00cvss 5.5epss 0.00
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
- risk 0.00cvss 5.5epss 0.01
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
- risk 0.00cvss 8.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
- risk 0.00cvss 7.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
- risk 0.00cvss 5.5epss 0.01
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.
- risk 0.00cvss 7.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.