CWE-823
104 CVEs • Abstraction: Base
Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
CVEs (104)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in...Show more |
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences...Show more |
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default...Show more |
1Qualcomm 18Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcc2072 Firmware+15 moreJun 17, 2026 Oct 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing an escape call. |
1Qualcomm 25Immersive Home 214 Platform Firmware Immersive Home 216 Platform FirmwareImmersive Home 316 Platform Firmware+22 moreJun 17, 2026 Oct 9, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Memory corruption while performing SCM call. |
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt...Show more |
1Qualcomm 4Sdm429w Firmware Snapdragon 429 Mobile Platform FirmwareWcn3620 Firmware+1 moreJun 17, 2026 Jun 3, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Memory corruption while handling test pattern generator IOCTL command. |
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory. |
1Qualcomm 57C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+54 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur during IO configuration processing when the IO port count is invalid. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
1Qualcomm 60Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+57 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation. |
1Qualcomm 41Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+38 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcc2073 Firmware+7 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. |
1Qualcomm 24Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+21 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occour while generating test pattern due to negative indexing of display ID. |
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory. |