CWE-1260Base

Improper Handling of Overlap Between Protected Memory Ranges

Stable in the CWE catalog · 14 CVEs mapped

14
CVEs mapped
6.9
Median CVSS
What it is

The product allows address regions to overlap, which can result in the bypassing of intended memory protection.

Recent examples
none
CVE-2026-20760

CVE-2026-20760 - UNKNOWN Severity Vulnerability

Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

no explanation yet
0%
epss
none
CVE-2025-31936

CVE-2025-31936 - UNKNOWN Severity Vulnerability

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

no explanation yet
0%
epss
6.9cvss
CVE-2018-25240

Watchr 1.1.0.0 Denial of Service via Search

Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause the application to crash.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1260
Abstraction
Base
Structure
Simple
Status
Stable
References (3)