CWE-823
58 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-823page 1 of 2
- CVE-2017-11076CRITICALCVSS 9.8EG 9.82024-11-26
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
- CVE-2020-13573HIGHCVSS 7.5EG 7.52021-01-07
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a seque…
- CVE-2020-27009HIGHCVSS 8.1EG 8.12021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2020-6112HIGHCVSS 7.8EG 7.82020-09-17
An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application ca…
- CVE-2020-8904MEDIUMCVSS 6.4EG 6.42020-08-12
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_le…
- CVE-2021-1352HIGHCVSS 7.4EG 6.52021-03-24
A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d…
- CVE-2021-22549MEDIUMCVSS 6.5EG 7.82021-06-08
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c
- CVE-2021-22550MEDIUMCVSS 6.5EG 6.52021-06-08
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd2…
- CVE-2021-34595HIGHCVSS 8.1EG 8.12021-10-26
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
- CVE-2021-3888HIGHCVSS 8.1EG 8.12021-10-19
libmobi is vulnerable to Use of Out-of-range Pointer Offset
- CVE-2021-3889HIGHCVSS 8.1EG 8.12021-10-19
libmobi is vulnerable to Use of Out-of-range Pointer Offset
- CVE-2022-0554HIGHCVSS 7.8EG 7.82022-02-10
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0614MEDIUMCVSS 5.5EG 5.52022-02-16
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.
- CVE-2022-0685HIGHCVSS 7.8EG 7.82022-02-20
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
- CVE-2022-0729HIGHCVSS 8.8EG 8.82022-02-23
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
- CVE-2022-1420MEDIUMCVSS 5.5EG 5.52022-04-21
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
- CVE-2022-21147MEDIUMCVSS 5.5EG 5.52022-05-12
An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-crafted PE file can trigger this vulnerability to cause denial of service and termination of malware scan. An attacker can p…
- CVE-2022-25694HIGHCVSS 8.4EG 7.82023-03-10
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- CVE-2022-25709HIGHCVSS 8.4EG 7.82023-03-10
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
- CVE-2022-32142HIGHCVSS 8.1EG 8.12022-06-24
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service co…
- CVE-2022-33246MEDIUMCVSS 6.7EG 7.82023-02-12
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.
- CVE-2022-42264HIGHCVSS 7.1EG 7.12022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclos…
- CVE-2022-43665MEDIUMCVSS 5.5EG 5.52023-02-02
A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-crafted PE file can lead to killing target process. An attacker can provide a malicious file to trigger this vulnerability.
- CVE-2022-46377MEDIUMCVSS 6.5EG 6.52023-05-10
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets …
- CVE-2022-46378MEDIUMCVSS 6.5EG 6.52023-05-10
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets …
- CVE-2023-20187HIGHCVSS 8.6EG 8.62023-09-27
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload…
- CVE-2023-22387HIGHCVSS 7.8EG 7.82023-07-04
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
- CVE-2023-22388CRITICALCVSS 9.8EG 9.82023-11-07
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- CVE-2023-2426MEDIUMCVSS 5.5EG 6.82023-04-29
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
- CVE-2023-24855CRITICALCVSS 9.8EG 9.82023-10-03
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- CVE-2023-28564HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
- CVE-2023-28575MEDIUMCVSS 6.7EG 6.72023-08-08
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
- CVE-2023-33033HIGHCVSS 8.4EG 8.42024-01-02
Memory corruption in Audio during playback with speaker protection.
- CVE-2023-33066HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption in Audio while processing RT proxy port register driver.
- CVE-2023-33067MEDIUMCVSS 6.7EG 6.72024-02-06
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
- CVE-2023-33079HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption in Audio while running invalid audio recording from ADSP.
- CVE-2023-33106HIGHCVSS 8.4EG 8.4⚠ KEV2023-12-05
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- CVE-2023-33110HIGHCVSS 7.8EG 7.82024-01-02
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session inde…
- CVE-2023-43513HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- CVE-2023-43516HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption when malformed message payload is received from firmware.
- CVE-2023-43534HIGHCVSS 8.6EG 8.62024-02-06
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- CVE-2023-43553CRITICALCVSS 9.8EG 9.82024-03-04
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
- CVE-2023-46724HIGHCVSS 8.6EG 8.62023-11-01
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Ce…
- CVE-2023-6560MEDIUMCVSS 5.5EG 5.52023-12-09
An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system.
- CVE-2024-1013HIGHCVSS 7.8EG 7.12024-03-18
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broke…
- CVE-2024-21475HIGHCVSS 7.8EG 7.82024-05-06
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- CVE-2024-23377MEDIUMCVSS 6.7EG 6.72024-11-04
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
- CVE-2024-33036MEDIUMCVSS 6.7EG 6.72024-12-02
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- CVE-2024-42383MEDIUMCVSS 4.2EG 4.22024-11-18
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
- CVE-2024-42386HIGHCVSS 8.2EG 8.22024-11-18
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Map vulnerabilities like CWE-823 to your infrastructure
EchelonGraph correlates every CVE — across CWE-823 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →