CWE-125
9,136 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,136)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jan 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vul...Show more |
4Mariadb OpensusePcre+1 more4Mariadb OpensusePcre+1 moreNov 21, 2024 Jan 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward...Show more |
4Mariadb OpensusePcre+1 more4Mariadb OpensusePcre+1 moreNov 21, 2024 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a...Show more |
1Gonitro 1Nitro Free Pdf Reader Jun 17, 2026 Jan 10, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content. |
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c. |
Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. |
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c. |
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. |
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8. |
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT. |
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8. |
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table. |
2Gnu Opensuse3Backports Sle LeapLibredwgJun 17, 2026 Jan 8, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c. |
2Gnu Opensuse3Backports Sle LeapLibredwgJun 17, 2026 Jan 8, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. |
2Gnu Opensuse3Backports Sle LeapLibredwgJun 17, 2026 Jan 8, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. |
2Gnu Opensuse3Backports Sle LeapLibredwgJun 17, 2026 Jan 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. |
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges need...Show more |
4Canonical DebianFreedesktop+1 more4Debian Linux LeapLibbsd+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab). |
2Libsdl Redhat2Enterprise Linux Simple Directmedia LayerJun 17, 2026 Jan 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-base...Show more |
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c. |