CWE-125
9,161 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Gstreamer Gstreamer ProjectNetapp+1 more13Active Iq Unified Manager E Series Santricity Os ControllerE Series Santricity Storage Manager+10 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. |
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part Ch...Show more |
3Datakit LuxionSiemens4Crosscadware KeyshotSolid Edge Se2020 Firmware+1 moreJun 17, 2026 May 27, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute...Show more |
GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c. |
A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC bytes from it. The length of the buffer is controlled by an attacker. By providing a length smaller...Show more |
A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This mi...Show more |
A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kerne...Show more |
Possible read out of bounds in dns read. Zephyr versions >= 1.14.2, >= 2.3.0 contain Out-of-bounds Read (CWE-125). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mm57-9hqw...Show more |
2Codesys Wago29750 8202 Firmware 750 8203 Firmware750 8204 Firmware+26 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. |
1Bytecodealliance 1Cranelift Codegen Jun 17, 2026 May 24, 2021 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend...Show more |
1Vmware 2Horizon Client WorkstationJun 17, 2026 May 24, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a v...Show more |
1Vmware 2Horizon Client WorkstationJun 17, 2026 May 24, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access t...Show more |
1Vmware 2Horizon Client WorkstationJun 17, 2026 May 24, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a v...Show more |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availabilit...Show more |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |