← Back
CWE-823

104 CVEs • Abstraction: Base

Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

JSON object

Loading...

CVEs (104)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Color
1Iccdev
Jun 17, 2026
Jan 6, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in...Show more
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in version 2.3.1.2.Show less
-
-
Nov 14, 2025
Nov 12, 2025
8.6 HIGH· v4
N/A· v3
N/A· v2
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences...Show more
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file).Show less
-
-
Jun 17, 2026
Oct 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default...Show more
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly. This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.Show less
1Qualcomm
18Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQcc2072 Firmware+15 more
Jun 17, 2026
Oct 9, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing an escape call.
1Qualcomm
25Immersive Home 214 Platform Firmware
Immersive Home 216 Platform FirmwareImmersive Home 316 Platform Firmware+22 more
Jun 17, 2026
Oct 9, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Memory corruption while performing SCM call.
-
-
Jun 17, 2026
Jul 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt...Show more
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.Show less
1Qualcomm
4Sdm429w Firmware
Snapdragon 429 Mobile Platform FirmwareWcn3620 Firmware+1 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Memory corruption while handling test pattern generator IOCTL command.
-
-
Jun 17, 2026
Jun 2, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.
-
-
Jun 17, 2026
May 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.
1Qualcomm
57C V2x 9150 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+54 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
1Imaginationtech
1Ddk
Jun 17, 2026
Apr 18, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
1Qualcomm
60Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+57 more
Jun 17, 2026
Apr 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
1Qualcomm
41Ar8035 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+38 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
-
-
Jun 17, 2026
Feb 22, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.
-
-
Jun 17, 2026
Feb 22, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
-
-
Jun 17, 2026
Feb 22, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
1Qualcomm
10Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQcc2073 Firmware+7 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
1Qualcomm
24Fastconnect 6700 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+21 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
-
-
Jun 17, 2026
Jan 31, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
-
-
Jun 17, 2026
Jan 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.