Vulnerabilities (CVE)

Filtered by CWE-125
Total 9030 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39387 3 Adobe, Apple, Microsoft 3 Bridge, Macos, Windows 2026-06-17 N/A 5.5 MEDIUM
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-39382 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2026-06-17 N/A 5.5 MEDIUM
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-39379 1 Adobe 1 Acrobat 2026-06-17 N/A 5.5 MEDIUM
Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-39277 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.8 HIGH
In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: handle NUMA_NO_NODE correctly cpumask_of_node() can be called for NUMA_NO_NODE inside do_map_benchmark() resulting in the following sanitizer report: UBSAN: array-index-out-of-bounds in ./arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type 'cpumask [64][1]' CPU: 1 PID: 990 Comm: dma_map_benchma Not tainted 6.9.0-rc6 #29 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dump_stack_lvl (lib/dump_stack.c:117) ubsan_epilogue (lib/ubsan.c:232) __ubsan_handle_out_of_bounds (lib/ubsan.c:429) cpumask_of_node (arch/x86/include/asm/topology.h:72) [inline] do_map_benchmark (kernel/dma/map_benchmark.c:104) map_benchmark_ioctl (kernel/dma/map_benchmark.c:246) full_proxy_unlocked_ioctl (fs/debugfs/file.c:333) __x64_sys_ioctl (fs/ioctl.c:890) do_syscall_64 (arch/x86/entry/common.c:83) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Use cpumask_of_node() in place when binding a kernel thread to a cpuset of a particular node. Note that the provided node id is checked inside map_benchmark_ioctl(). It's just a NUMA_NO_NODE case which is not handled properly later. Found by Linux Verification Center (linuxtesting.org).
CVE-2024-38797 2026-06-17 N/A 4.6 MEDIUM
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
CVE-2024-38658 2026-06-17 N/A 7.8 HIGH
There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
CVE-2024-38654 1 Ivanti 1 Secure Access Client 2026-06-17 N/A 4.4 MEDIUM
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
CVE-2024-38649 1 Ivanti 1 Connect Secure 2026-06-17 N/A 7.5 HIGH
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-38585 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.1 HIGH
In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of heap->len to prevent realloc() from copying an extra sizeof(heap) bytes from beyond the allocated region.
CVE-2024-38560 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.1 HIGH
In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but we don't ensure that the string is terminated inside the buffer, this can lead to OOB read when using sscanf. Fix this issue by using memdup_user_nul instead of memdup_user.
CVE-2024-38481 1 Dell 1 Emc Idrac Service Module 2026-06-17 N/A 4.8 MEDIUM
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
CVE-2024-38417 1 Qualcomm 112 Ar8035, Ar8035 Firmware, C-v2x 9150 and 109 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while processing IO control commands.
CVE-2024-38416 1 Qualcomm 144 Ar8035, Ar8035 Firmware, C-v2x 9150 and 141 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure during audio playback.
CVE-2024-38414 1 Qualcomm 58 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 55 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while processing information on firmware image during core initialization.
CVE-2024-38405 1 Qualcomm 198 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 195 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while processing the CU information from RNR IE.
CVE-2024-38404 1 Qualcomm 80 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 77 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
CVE-2024-38403 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 153 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-38397 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 229 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame.
CVE-2024-38389 2026-06-17 N/A 7.8 HIGH
There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
CVE-2024-38382 1 Openatom 1 Openharmony 2026-06-17 N/A 5.5 MEDIUM
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.