Vulnerabilities (CVE)

Filtered by CWE-125
Total 7228 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-34222 3 Adobe, Apple, Microsoft 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more 2024-11-21 N/A 7.8 HIGH
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-34215 3 Adobe, Apple, Microsoft 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more 2024-11-21 N/A 7.8 HIGH
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-34145 1 Qualcomm 188 Csr8811, Csr8811 Firmware, Ipq5010 and 185 more 2024-11-21 N/A 7.5 HIGH
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
CVE-2022-34037 1 Caddyserver 1 Caddy 2024-11-21 N/A 7.5 HIGH
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.
CVE-2022-34029 1 F5 1 Njs 2024-11-21 N/A 9.1 CRITICAL
Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.
CVE-2022-33968 1 F5 11 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 8 more 2024-11-21 N/A 3.7 LOW
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, when an LTM monitor or APM SSO is configured on a virtual server, and NTLM challenge-response is in use, undisclosed traffic can cause a buffer over-read. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2022-33884 1 Autodesk 10 Autocad, Autocad Advance Steel, Autocad Architecture and 7 more 2024-11-21 N/A 7.5 HIGH
Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2022-33881 1 Autodesk 10 Autocad, Autocad Advance Steel, Autocad Architecture and 7 more 2024-11-21 N/A 7.8 HIGH
Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2022-33717 1 Google 1 Android 2024-11-21 N/A 4.4 MEDIUM
A missing input validation before memory read in SEM TA prior to SMR Aug-2022 Release 1 allows local attackers to read out of bound memory.
CVE-2022-33319 2 Iconics, Mitsubishielectric 2 Genesis64, Mc Works64 2024-11-21 N/A 9.1 CRITICAL
Out-of-bounds Read vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64 server.
CVE-2022-33309 1 Qualcomm 130 Csr8811, Csr8811 Firmware, Ipq5010 and 127 more 2024-11-21 N/A 7.5 HIGH
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
CVE-2022-33306 1 Qualcomm 262 Ar8035, Ar8035 Firmware, Ar9380 and 259 more 2024-11-21 N/A 7.5 HIGH
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
CVE-2022-33297 1 Qualcomm 20 Qca6310, Qca6310 Firmware, Qca6320 and 17 more 2024-11-21 N/A 6.8 MEDIUM
Information disclosure due to buffer overread in Linux sensors
CVE-2022-33295 1 Qualcomm 24 Mdm8207, Mdm8207 Firmware, Mdm9205 and 21 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
CVE-2022-33291 1 Qualcomm 78 9205 Lte Modem, 9205 Lte Modem Firmware, 9206 Lte Modem and 75 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
CVE-2022-33287 1 Qualcomm 78 9205 Lte Modem, 9205 Lte Modem Firmware, 9206 Lte Modem and 75 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
CVE-2022-33273 1 Qualcomm 198 Aqt1000, Aqt1000 Firmware, Ar8035 and 195 more 2024-11-21 N/A 7.3 HIGH
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
CVE-2022-33271 1 Qualcomm 490 Apq8096au, Apq8096au Firmware, Aqt1000 and 487 more 2024-11-21 N/A 8.2 HIGH
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
CVE-2022-33258 1 Qualcomm 24 Mdm8207, Mdm8207 Firmware, Mdm9205 and 21 more 2024-11-21 N/A 8.2 HIGH
Information disclosure due to buffer over-read in modem while reading configuration parameters.
CVE-2022-33229 1 Qualcomm 42 Ar8031, Ar8031 Firmware, Csra6620 and 39 more 2024-11-21 N/A 8.2 HIGH
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.