Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2023-04-21 CVE-2023-2226 Out-of-bounds Read vulnerability in Rapid7 Velociraptor
Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files.  For this attack to succeed, the attacker needs to be able to introduce malicious files to the system at the same time that Velociraptor attempts to collect any artifacts that attempt to parse PE files, Authenticode signatures, or OLE files.
network
low complexity
rapid7 CWE-125
5.3
2023-04-20 CVE-2023-2176 Out-of-bounds Read vulnerability in Linux Kernel
A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel.
local
low complexity
linux CWE-125
7.8
2023-04-20 CVE-2023-22295 Out-of-bounds Read vulnerability in Datakit Crosscadware 2021.1
Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file.
local
low complexity
datakit CWE-125
5.5
2023-04-20 CVE-2023-22321 Out-of-bounds Read vulnerability in Datakit Crosscadware 2021.1
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file.
local
low complexity
datakit CWE-125
5.5
2023-04-20 CVE-2023-22354 Out-of-bounds Read vulnerability in Datakit Crosscadware 2021.1
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file.
local
low complexity
datakit CWE-125
5.5
2023-04-20 CVE-2023-22846 Out-of-bounds Read vulnerability in Datakit Crosscadware 2021.1
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file.
local
low complexity
datakit CWE-125
5.5
2023-04-20 CVE-2023-1255 Out-of-bounds Read vulnerability in Openssl
Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it to read past the input buffer, leading to a crash. Impact summary: Applications that use the AES-XTS algorithm on the 64 bit ARM platform can crash in rare circumstances.
network
high complexity
openssl CWE-125
5.9
2023-04-19 CVE-2023-20935 Out-of-bounds Read vulnerability in Google Android
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2023-04-19 CVE-2023-21080 Out-of-bounds Read vulnerability in Google Android
In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2023-04-17 CVE-2023-27906 Out-of-bounds Read vulnerability in Autodesk Maya USD
A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerability which may result in code execution.
local
low complexity
autodesk CWE-125
7.8