← Back
CWE-823

104 CVEs • Abstraction: Base

Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

JSON object

Loading...

CVEs (104)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
130Ar8035 Firmware
Csr8811 FirmwareFastconnect 6900 Firmware+127 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
1Qualcomm
307205 Mobile Firmware
215 Mobile Firmware315 5g Iot Modem Firmware+304 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while processing RT proxy port register driver.
1Qualcomm
65Ar8035 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+62 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
1Qualcomm
8Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQcm8550 Firmware+5 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when malformed message payload is received from firmware.
1Qualcomm
261315 5g Iot Modem Firmware
Apq8017 FirmwareAqt1000 Firmware+258 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
1Qualcomm
1109206 Lte Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+107 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
1Qualcomm
118Snapdragon 425 Mobile Platform Firmware
Snapdragon 427 Mobile Platform FirmwareSnapdragon 429 Mobile Platform Firmware+115 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and...Show more
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.Show less
1Qualcomm
259315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+256 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio during playback with speaker protection.
1Linux
1Linux Kernel
Jun 17, 2026
Dec 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system.
1Qualcomm
147Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+144 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
1Qualcomm
143Apq5053 Aa Firmware
Ar8035 FirmwareCsra6620 Firmware+140 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while running invalid audio recording from ADSP.
1Qualcomm
223315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+220 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
1Squid Cache
1Squid
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service at...Show more
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.Show less
1Qualcomm
61Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+58 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
1Cisco
1Ios Xe
Jun 17, 2026
Sep 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affect...Show more
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition.Show less
1Qualcomm
247Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+244 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
1Qualcomm
59205 Firmware
215 FirmwareAqt1000 Firmware+56 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
1Qualcomm
266205 Firmware
215 Firmware315 5g Iot Firmware+263 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
1Weston Embedded
1Uc Ftps
Jun 17, 2026
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacke...Show more
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no port argument is provided to the `PORT` command.Show less
1Weston Embedded
1Uc Ftps
Jun 17, 2026
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacke...Show more
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.Show less