CWE-786Base

Access of Memory Location Before Start of Buffer

Incomplete in the CWE catalog · 4 CVEs mapped

4
CVEs mapped
7.3
Median CVSS
What it is

The product reads or writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Recent examples
5.8cvss
CVE-2026-20058

CVE-2026-20058 - MEDIUM Severity Vulnerability

Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition.

MEDIUMno explanation yet
0%
epss
8.6cvss
CVE-2023-46724

SQUID-2023:4 Denial of Service in SSL Certificate validation

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

HIGHno explanation yet
4%
epss
6.3cvss
CVE-2022-0522

Access of Memory Location Before Start of Buffer in radareorg/radare2

Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

MEDIUMno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-786
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)