CWE-125
9,136 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,136)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. |
3Canonical DebianFedoraproject4Apt Debian LinuxFedora+1 moreJun 17, 2026 May 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files. |
1Huawei 4Honor 20 Firmware Honor 20 Pro FirmwareHonor Magic2 Firmware+1 moreJun 17, 2026 May 15, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier...Show more |
In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to local information disclosure of data from a privileged process with no additional execution privilege...Show more |
5Canonical DebianGoogle+2 more5Android Debian LinuxLeap+2 moreJun 17, 2026 May 14, 2020 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 12, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an...Show more |
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Infor...Show more |
1Symantec 1Endpoint Protection Manager Jun 17, 2026 May 11, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memo...Show more |
4Canonical DebianExim+1 more4Debian Linux EximFedora+1 moreJun 17, 2026 May 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c. |
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 May 8, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c. |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 3.3 LOW· v3 4.9 MEDIUM· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This...Show more |