← Back
CWE-125

9,172 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,172)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openscad
1Openscad
Jun 17, 2026
Aug 29, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().
1Linux
1Linux Kernel
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.
1Imagemagick
1Imagemagick
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) im...Show more
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.Show less
1Tcpdump
1Tcpdump
Jun 17, 2026
Aug 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
1Upx
1Upx
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
1Upx
1Upx
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
1Upx
1Upx
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.
1Upx
1Upx
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
1Cisco
146Nexus 3016 Firmware
Nexus 3016q FirmwareNexus 3048 Firmware+143 more
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.6 HIGH· v3
N/A· v2
A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due...Show more
A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending a malicious OSPFv3 link-state advertisement (LSA) to an affected device. A successful exploit could allow the attacker to cause the OSPFv3 process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The OSPFv3 feature is disabled by default. To exploit this vulnerability, an attacker must be able to establish a full OSPFv3 neighbor state with an affected device. For more information about exploitation conditions, see the Details section of this advisory.Show less
1Samba
1Samba
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
2Gnu
Netapp
7Glibc
H300s FirmwareH410c Firmware+4 more
Jun 17, 2026
Aug 24, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
3Dpdk
FedoraprojectRedhat
4Data Plane Development Kit
Enterprise LinuxEnterprise Linux Fast Datapath+1 more
Jun 17, 2026
Aug 23, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost l...Show more
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.Show less
1Hdfgroup
1Hdf5
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulne...Show more
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Qt
1Qt
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG...Show more
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.Show less
1Intel
3Proset Wi Fi 6e Ax210 Firmware
Wi Fi 6e Ax211 FirmwareWi Fi 6e Ax411 Firmware
Jun 17, 2026
Aug 18, 2022
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Out of bounds read for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable information disclosure via local access.
1Intel
18Dual Band Wireless Ac 3165 Firmware
Dual Band Wireless Ac 3168 FirmwareDual Band Wireless Ac 8260 Firmware+15 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
9Killer Ac 1550 Firmware
Killer Wi Fi 6 Ax1650 FirmwareKiller Wi Fi 6e Ax1675 Firmware+6 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.
1Intel
18Dual Band Wireless Ac 3165 Firmware
Dual Band Wireless Ac 3168 FirmwareDual Band Wireless Ac 8260 Firmware+15 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access.
1Intel
18Dual Band Wireless Ac 3165 Firmware
Dual Band Wireless Ac 3168 FirmwareDual Band Wireless Ac 8260 Firmware+15 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Upx
1Upx
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading...Show more
An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.Show less