CWE-1260: Improper Handling of Overlap Between Protected Memory Ranges
The product allows address regions to overlap, which can result in the bypassing of intended memory protection.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-22889 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow
- CVE-2025-0012 — Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could
- CVE-2019-25602 — GSearch 1.0.1.0 Denial of Service via Search Input
- CVE-2019-25570 — RealTerm Serial Terminal 2.0.0.70 Denial of Service via Port Field
- CVE-2019-25559 — SpotPaltalk 1.1.5 Name/Key Field Denial of Service
- CVE-2025-29948 — Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R)
- CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring
Recently published
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R)
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring
- CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2019-25602 — GSearch 1.0.1.0 Denial of Service via Search Input
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow
- CVE-2019-25570 — RealTerm Serial Terminal 2.0.0.70 Denial of Service via Port Field
- CVE-2019-25559 — SpotPaltalk 1.1.5 Name/Key Field Denial of Service
- CVE-2025-0012 — Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could
- CVE-2025-29948 — Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa
- CVE-2025-22889 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may