CWE-823
104 CVEs • Abstraction: Base
Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
CVEs (104)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
1Qualcomm 34Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQam8295p Firmware+31 moreJun 17, 2026 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |
1Qualcomm 51C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 moreJun 17, 2026 Dec 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. |
1Qualcomm 27Msm8909w Firmware Msm8996au FirmwareSd 205 Firmware+24 moreJan 9, 2025 Nov 26, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. |
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. |
1Qualcomm 38Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQca6391 Firmware+35 moreJun 17, 2026 Nov 4, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver. |
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that...Show more |
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <...Show more |
1Qualcomm 229215 Mobile Firmware 315 5g Iot Modem FirmwareAqt1000 Firmware+226 moreJun 17, 2026 May 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when the payload received from firmware is not as per the expected protocol size. |
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian archite...Show more |