CWE-788Base

Access of Memory Location After End of Buffer

Incomplete in the CWE catalog · 144 CVEs mapped

144
CVEs mapped
7.8
Median CVSS
What it is

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

Recent examples
5.6cvss
CVE-2023-20585

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds…

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.

MEDIUMno explanation yet
0%
epss
5.8cvss
CVE-2026-20052

CVE-2026-20052 - MEDIUM Severity Vulnerability

A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet inspection. An attacker could exploit this vulnerability by sending crafted SSL packets through an established connection to be parsed by the Snort 3 Detection Engine. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when the Snort 3 Detection Engine unexpectedly restarts.

MEDIUMno explanation yet
0%
epss
5.5cvss
CVE-2026-21316

CVE-2026-21316 - MEDIUM Severity Vulnerability

Audition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-788
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)