CWE-823— Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.— MITRE CWE catalog
108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-823page 1 of 3
- CVE-2023-33106CRITICALCVSS 8.4EG 9.0⚠ KEV2023-12-05
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- CVE-2017-11076CRITICALCVSS 9.8EG 9.82024-11-26
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
- CVE-2023-43553CRITICALCVSS 9.8EG 9.82024-03-04
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
- CVE-2023-22388CRITICALCVSS 9.8EG 9.82023-11-07
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- CVE-2023-24855CRITICALCVSS 9.8EG 9.82023-10-03
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- CVE-2026-21732CRITICALCVSS 9.6EG 9.62026-03-20
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privi…
- CVE-2026-46244CRITICALCVSS 9.1EG 9.12026-06-03
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header …
- CVE-2026-72642HIGHCVSS 8.8EG 8.82026-08-13
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays w…
- CVE-2025-27059HIGHCVSS 8.8EG 8.82025-10-09
Memory corruption while performing SCM call.
- CVE-2024-42416HIGHCVSS 8.8EG 8.82024-09-05
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scs…
- CVE-2022-0729HIGHCVSS 8.8EG 8.82022-02-23
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
- CVE-2017-20211HIGHCVSS 8.6EG 8.62025-11-12
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied poi…
- CVE-2023-43534HIGHCVSS 8.6EG 8.62024-02-06
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- CVE-2023-20187HIGHCVSS 8.6EG 8.62023-09-27
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload…
- CVE-2026-102757HIGHCVSS 8.5EG 8.52026-09-29
An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module …
- CVE-2023-33066HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption in Audio while processing RT proxy port register driver.
- CVE-2023-33033HIGHCVSS 8.4EG 8.42024-01-02
Memory corruption in Audio during playback with speaker protection.
- CVE-2022-25709HIGHCVSS 8.4EG 8.42023-03-10
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
- CVE-2022-25694HIGHCVSS 8.4EG 8.42023-03-10
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- CVE-2025-0467HIGHCVSS 8.2EG 8.22025-04-18
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
- CVE-2024-42386HIGHCVSS 7.5EG 8.22024-11-18
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
- CVE-2026-12290HIGHCVSS 8.1EG 8.12026-06-16
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- CVE-2022-32142HIGHCVSS 8.1EG 8.12022-06-24
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service co…
- CVE-2021-34595HIGHCVSS 8.1EG 8.12021-10-26
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
- CVE-2021-3889HIGHCVSS 8.1EG 8.12021-10-19
libmobi is vulnerable to Use of Out-of-range Pointer Offset
- CVE-2021-3888HIGHCVSS 8.1EG 8.12021-10-19
libmobi is vulnerable to Use of Out-of-range Pointer Offset
- CVE-2020-27009HIGHCVSS 8.1EG 8.12021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2026-45199HIGHCVSS 7.8EG 7.82026-08-21
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands …
- CVE-2026-49745HIGHCVSS 7.8EG 7.82026-07-24
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands …
- CVE-2026-49744HIGHCVSS 7.8EG 7.82026-07-24
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Gu…
- CVE-2026-28764HIGHCVSS 7.8EG 7.82026-05-21
A heap-based buffer overflow vulnerability exists in the LXF element parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to…
- CVE-2025-47349HIGHCVSS 7.8EG 7.82025-10-09
Memory corruption while processing an escape call.
- CVE-2025-25180HIGHCVSS 7.8EG 7.82025-07-14
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allo…
- CVE-2024-45557HIGHCVSS 7.8EG 7.82025-04-07
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
- CVE-2024-43060HIGHCVSS 7.8EG 7.82025-03-03
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
- CVE-2024-52939HIGHCVSS 7.8EG 7.82025-02-22
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.
- CVE-2024-49840HIGHCVSS 7.8EG 7.82025-02-03
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
- CVE-2024-45573HIGHCVSS 7.8EG 7.82025-02-03
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
- CVE-2024-47900HIGHCVSS 7.8EG 7.82025-01-31
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
- CVE-2024-52938HIGHCVSS 7.8EG 7.82025-01-13
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.
- CVE-2024-21475HIGHCVSS 7.8EG 7.82024-05-06
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- CVE-2024-1013HIGHCVSS 7.8EG 7.82024-03-18
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broke…
- CVE-2023-43516HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption when malformed message payload is received from firmware.
- CVE-2023-43513HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- CVE-2023-33110HIGHCVSS 7.8EG 7.82024-01-02
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session inde…
- CVE-2023-33079HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption in Audio while running invalid audio recording from ADSP.
- CVE-2023-28564HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
- CVE-2023-22387HIGHCVSS 7.8EG 7.82023-07-04
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
- CVE-2022-0685HIGHCVSS 7.8EG 7.82022-02-20
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
- CVE-2022-0554HIGHCVSS 7.8EG 7.82022-02-10
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
Map vulnerabilities like CWE-823 to your infrastructure
EchelonGraph correlates every CVE — across CWE-823 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →