CWE-466Base

Return of Pointer Value Outside of Expected Range

Draft in the CWE catalog · 8 CVEs mapped

8
CVEs mapped
6.9
Median CVSS
What it is

A function can return a pointer to memory that is outside of the buffer that the pointer is expected to reference.

Recent examples
6.8cvss
CVE-2026-57025

Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.

MEDIUMno explanation yet
0%
epss
6.9cvss
CVE-2018-25234

SmartFTP Client 9.0.2615.0 Denial of Service via Host Field

SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application crash.

MEDIUMno explanation yet
0%
epss
6.9cvss
CVE-2018-25227

Valentina Studio 9.0.4 Denial of Service via Host Parameter

Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-466
Abstraction
Base
Structure
Simple
Status
Draft
References (2)