CWE-823: Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
100 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-21732 — GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation
- CVE-2025-27059 — Use of Out-of-range Pointer Offset in TZ Firmware
- CVE-2025-47349 — Use of Out-of-range Pointer Offset in DSP Service
- CVE-2024-49840 — Use of Out-of-range Pointer Offset in WLAN Windows Host
- CVE-2024-43060 — Use of Out-of-range Pointer Offset in Automotive Audio
- CVE-2024-1013 — Unixodbc: out of bounds stack write due to pointer-to-integer types conversion
- CVE-2025-11232 — Invalid characters cause assert
- CVE-2026-72642 — Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
- CVE-2026-42946 — NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
- CVE-2025-46806 — Misaligned Memory Accesses in `is_openvpn_protocol()`
- CVE-2026-32829 — lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
- CVE-2024-42386 — Use of Out-of-range Pointer Offset in Mongoose Web Server library
- CVE-2025-33215 — NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of
- CVE-2026-41907 — uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
- CVE-2024-33041 — Use of Out-of-range Pointer Offset in Computer Vision
- CVE-2024-33036 — Use of Out-of-range Pointer Offset in Camera Driver
- CVE-2024-23377 — Use of Out-of-range Pointer Offset in ComputerVision
- CVE-2024-53017 — Use of Out-of-range Pointer Offset in Camera Driver
- CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
- CVE-2026-49745 — GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
Recently published
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
- CVE-2026-72642 — Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
- CVE-2026-49746 — GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem
- CVE-2026-49745 — GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
- CVE-2026-49744 — GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()
- CVE-2026-21734 — GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
- CVE-2026-34193 — GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()
- CVE-2026-28764 — MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
- CVE-2026-42946 — NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
- CVE-2026-41907 — uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
- CVE-2025-33215 — NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of
- CVE-2026-21732 — GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation
- CVE-2026-32829 — lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
- CVE-2026-20022 — A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
- CVE-2025-54152 — Qsync Central
- CVE-2026-23764 — VB-Audio Voicemeeter & Matrix Drivers DoS via Corrupted IoAllocateMdl Length
- CVE-2026-21487 — iccDEV has Out-of-bounds Read, Use of Out-of-range Pointer Offset and Improper Input Validation
- CVE-2025-11232 — Invalid characters cause assert
- CVE-2025-47349 — Use of Out-of-range Pointer Offset in DSP Service