← Back
CWE-823

98 CVEs • Abstraction: Base

Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

JSON object

Loading...

CVEs (98)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
51C V2x 9150 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 more
Jun 17, 2026
Dec 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
1Qualcomm
27Msm8909w Firmware
Msm8996au FirmwareSd 205 Firmware+24 more
Jan 9, 2025
Nov 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
1Cesanta
1Mongoose
Jun 17, 2026
Nov 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
1Qualcomm
38Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQca6391 Firmware+35 more
Jun 17, 2026
Nov 4, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
1Freebsd
1Freebsd
Jun 17, 2026
Sep 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that...Show more
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 9, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <...Show more
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.Show less
1Qualcomm
229215 Mobile Firmware
315 5g Iot Modem FirmwareAqt1000 Firmware+226 more
Jun 17, 2026
May 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when the payload received from firmware is not as per the expected protocol size.
1Unixodbc
1Unixodbc
Jun 17, 2026
Mar 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian archite...Show more
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.Show less
1Qualcomm
130Ar8035 Firmware
Csr8811 FirmwareFastconnect 6900 Firmware+127 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
1Qualcomm
307205 Mobile Firmware
215 Mobile Firmware315 5g Iot Modem Firmware+304 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while processing RT proxy port register driver.
1Qualcomm
65Ar8035 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+62 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
1Qualcomm
8Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQcm8550 Firmware+5 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when malformed message payload is received from firmware.
1Qualcomm
261315 5g Iot Modem Firmware
Apq8017 FirmwareAqt1000 Firmware+258 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
1Qualcomm
1109206 Lte Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+107 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.