CWE-823

Use of Out-of-range Pointer Offset

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

100 vulnerabilities with CWE-823
CVE-2024-45570 MEDIUM
Qualcomm Firmware - Memory Corruption during IO Configuration Processing
CVSS 6.6
CVE-2024-45557 HIGH
Qualcomm FastConnect and AR8035 Firmware - Memory Corruption in TME
CVSS 7.8
CVE-2024-43060 HIGH
Qualcomm Firmware - Memory Corruption during Voice Activation
CVSS 7.8
CVE-2024-52939 HIGH
Kernel software <Guest VM - Memory Corruption
CVSS 7.8
CVE-2024-47896 LOW
Kernel software <Guest VM - Memory Corruption
CVSS 3.3
CVE-2024-12577 HIGH
Imagination Technologies Graphics DDK 1.15 RTM-24.2 RTM & >=25.1 RTM - Memory Corruption
CVSS 7.3
CVE-2024-49840 HIGH
Qualcomm FastConnect and Multiple Firmware - Memory Corruption via IOCTL FIPS Validation
CVSS 7.8
CVE-2024-45573 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-47900 HIGH
Software <version> - Memory Corruption
CVSS 7.8
CVE-2024-52938 HIGH
Kernel software - Memory Corruption
CVSS 7.8
CVE-2024-52937 MEDIUM
Kernel software - Memory Corruption
CVSS 6.7
CVE-2024-52936 MEDIUM
Kernel software <Guest VM - Info Disclosure
CVSS 4.4
CVE-2024-52935 MEDIUM
Kernel software - Memory Corruption
CVSS 4.1
CVE-2024-47895 HIGH
Kernel software <Guest VM - Info Disclosure
CVSS 7.1
CVE-2024-47894 HIGH
Kernel software <Guest VM - Info Disclosure
CVSS 7.1
CVE-2024-33041 MEDIUM
Qualcomm FastConnect 6900 Firmware - Memory Corruption via Fence Frame IOCTL Calls
CVSS 6.7
CVE-2024-33036 MEDIUM
Qualcomm C-V2X 9150 Firmware - Memory Corruption via Sensor Packet Parsing
CVSS 6.7
CVE-2024-42391 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 4.3
CVE-2024-42390 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 4.3
CVE-2024-42389 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 5.3
CVE-2024-42388 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 5.3
CVE-2024-42387 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 5.3
CVE-2024-42386 HIGH
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 8.2
CVE-2024-42383 MEDIUM
Cesanta Mongoose Web Server <7.14 - Memory Corruption
CVSS 4.2
CVE-2024-23377 MEDIUM
Qualcomm WSA8845H and other Firmware - Memory Corruption via IOCTL Command Packet Size Modification
CVSS 6.7
Details
Vulnerabilities 100