CWE-125
9,136 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,136)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samsung 9Exynos 1080 Firmware Exynos 1280 FirmwareExynos 1330 Firmware+6 moreJun 17, 2026 Sep 9, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_sc...Show more |
1Samsung 9Exynos 1080 Firmware Exynos 1280 FirmwareExynos 1330 Firmware+6 moreJun 17, 2026 Sep 9, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_roamed_ind(), the...Show more |
The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution...Show more |
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so...Show more |
A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and al...Show more |
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()` When enabling UBSAN on Raspberry Pi 5, we get the following warning: [ 387.894977] UBSAN: arr...Show more |
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR. |
1Qualcomm 170Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+167 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
1Qualcomm 282315 5g Iot Firmware 9206 Lte FirmwareApq8017 Firmware+279 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
1Qualcomm 252Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+249 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
1Qualcomm 187Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+184 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
1Qualcomm 24Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+21 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when the captureRead QDCM command is invoked from user-space. |
1Qualcomm 197205 Mobile Platform Firmware 215 Mobile Platform FirmwareApq8017 Firmware+194 moreJun 17, 2026 Sep 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read. |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Sep 2, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Pa...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Sep 2, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Pa...Show more |
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful exploit of this vulnerability may cause an out of bounds read in the unp...Show more |