CWE-823

Total CVEs
74
Vulnerabilities
Avg CVSS v3
7.4
High
Avg CVSS v2
5.4
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 7
9.5%
High 48
64.9%
Medium 18
24.3%
Low 1
1.4%

External References

All CVEs (74)

Page 1 of 4
CVSS:9.8(Critical)

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

CVSS:9.8(Critical)

Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.

CVSS:9.8(Critical)

Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

CVSS:9.8(Critical)

Memory corruption in Modem while processing security related configuration before AS Security Exchange.

CVSS:9.8(Critical)

Memory Corruption in Multi-mode Call Processor while processing bit mask API.

CVSS:9.8(Critical)

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.

CVSS:9.6(Critical)

An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an at...

CVSS:8.8(High)

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles wit...

CVSS:8.4(High)

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

CVSS:8.4(High)

Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

CVSS:8.4(High)

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

CVSS:8.2(High)

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVSS:8.1(High)

Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write ac...

CVSS:8.1(High)

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-serv...

CVSS:8.1(High)

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5....

CVSS:7.8(High)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.

CVSS:7.8(High)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised G...

CVSS:7.8(High)

Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.

CVSS:7.8(High)

Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.

CVSS:7.8(High)

Memory corruption may occour while generating test pattern due to negative indexing of display ID.

CVSS:7.8(High)

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

CVSS:7.8(High)

Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.

CVSS:7.8(High)

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

CVSS:7.8(High)

Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,