CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,851 vulnerabilities with CWE-125
CVE-2024-54507 MEDIUM
iPadOS < 18.2 - Authenticated Out-of-bounds Read via Type Confusion
CVSS 5.5
CVE-2024-54478 MEDIUM
iPadOS < 17.7.4 - Out-of-bounds Read
CVSS 6.5
CVE-2024-24417 HIGH
Linux Foundation Magma <= 1.8.0 - Denial of Service via Crafted NAS Packet
CVSS 7.5
CVE-2024-57945 HIGH
Linux kernel 5.10.212-5.10.x - Out-of-bounds Read in RISC-V vmemmap Address Calculation
CVSS 7.1
CVE-2024-57928 HIGH
Linux Kernel 6.12-6.12.9 - Out-of-bounds Read in netfs Buffered Read Handling
CVSS 7.1
CVE-2024-48855 MEDIUM
QNX Software Development Platform 7.0-8.0 - Unauthenticated Out-of-bounds Read in TIFF Image Codec
CVSS 5.3
CVE-2024-13169 HIGH
Ivanti Endpoint Manager < 2022 SU6 - Authenticated Privilege Escalation via Out-of-bounds Read
CVSS 7.8
CVE-2024-46670 HIGH
FortiOS 7.2.0-7.2.9, 7.4.0-7.4.4, 7.6.0 - Unauthenticated Denial of Service via IPsec IKE Service
CVSS 7.5
CVE-2024-36504 MEDIUM
FortiOS 6.4-7.2.8, 7.4.0-7.4.4 - Authenticated Denial of Service via SSLVPN Web Portal URL
CVSS 6.5
CVE-2024-52332 HIGH
Linux Kernel 2.6.30-6.12.5 - Out-of-bounds Read in igb_init_module()
CVSS 7.1
CVE-2024-41935 HIGH
Linux Kernel - Out-of-bounds Read in F2FS Extent Tree Shrink
CVSS 7.1
CVE-2024-57822 MEDIUM
raptor_rdf_syntax_library <= 2.0.16 - Heap-Based Buffer Over-Read in N-Quads Parser
CVSS 4.0
CVE-2024-35532 CRITICAL
Intersec Geosafe-ea 2022.12-2022.14 - XML External Entity Injection
CVSS 9.1
CVE-2024-45070 MEDIUM
OpenHarmony <4.1.2 - Info Disclosure
CVSS 5.5
CVE-2024-48457 HIGH
Netis Wifi6 Router Multiple Versions - Out-of-bounds Read via /cgi-bin/skk_set.cgi
CVSS 7.5
CVE-2024-48456 HIGH
Netis Wifi Router - Info Disclosure
CVSS 7.5
CVE-2024-45559 MEDIUM
Qualcomm Firmware - Denial of Service via GVM Message to Vdev-FastRPC Backend
CVSS 5.5
CVE-2024-45558 HIGH
Qualcomm AR8035 Firmware - Denial of Service via Per STA Profile IE Parsing
CVSS 7.5
CVE-2024-45548 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-45546 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-43063 MEDIUM
Product <Version> - Info Disclosure
CVSS 6.1
CVE-2024-33067 MEDIUM
Qualcomm AR8035 and other Firmware - Out-of-bounds Read in Sound Model Driver Callback
CVSS 6.1
CVE-2024-33061 MEDIUM
Qualcomm QCS8550 Firmware - Information Disclosure via Uninitialized Process Handling in IOCTL Call
CVSS 6.8
CVE-2024-23366 MEDIUM
Qualcomm Firmware - Information Disclosure via Mailbox Write API
CVSS 6.6
CVE-2024-53839 MEDIUM
Protocol Net Adapter - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 8,851