CWE-823— Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.— MITRE CWE catalog
103 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-823page 3 of 3
- CVE-2026-49745HIGHCVSS 7.8EG 7.82026-07-24
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands …
- CVE-2026-49746HIGHCVSS 7.1EG 7.12026-08-07
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB …
- CVE-2026-72642HIGHCVSS 8.8EG 8.82026-08-13
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays w…
Map vulnerabilities like CWE-823 to your infrastructure
EchelonGraph correlates every CVE — across CWE-823 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →