CWE-468Base

Incorrect Pointer Scaling

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
9.8
Median CVSS
What it is

In C and C++, one may often accidentally refer to the wrong memory due to the semantics of when math operations are implicitly scaled.

Recent examples
7.1cvss
CVE-2026-34194

GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation. The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.

HIGHno explanation yet
0%
epss
9.8cvss
CVE-2024-1915

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…

🚨 A remote attacker can craft a packet to unleash malicious code on Mitsubishi MELSEC-Q and MELSEC-L Series CPU modules! 🔥 Think of a factory where the machinery runs on precise commands, like a symphony orchestra following a conductor's baton. If someone sends the wrong signals without authorization, they could throw the entire performance into chaos! An attacker could gain almost unfettered access, executing arbitrary code remotely, which could lead to devastating operational failures or unauthorized control over critical systems. It's like someone infiltrating the control room and pulling all the levers without anyone noticing!

CRITICAL
1%
epss
9.8cvss
CVE-2024-0802

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…

🚨 A crafty packet is all it takes to open the door to your Mitsubishi MELSEC systems! Think of it like an intruder who can sneak into a factory through a back door, reading confidential plans or even altering machinery settings without anyone noticing. This vulnerability allows remote attackers to access sensitive information or run malicious code as if they belonged there! An attacker could exploit this vulnerability to read arbitrary data from your CPU modules or execute harmful code, potentially compromising your entire system's integrity. This could lead to unauthorized operations, data breaches, and even operational downtime, which would be absolutely devastating for your organization.

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-468
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)