← Back
CWE-125

9,136 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,136)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jan 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vul...Show more
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0639.Show less
4Mariadb
OpensusePcre+1 more
4Mariadb
OpensusePcre+1 more
Nov 21, 2024
Jan 14, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward...Show more
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".Show less
4Mariadb
OpensusePcre+1 more
4Mariadb
OpensusePcre+1 more
Nov 21, 2024
Jan 14, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a...Show more
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.Show less
1Gonitro
1Nitro Free Pdf Reader
Jun 17, 2026
Jan 10, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
1Bftpd Project
1Bftpd
Jun 17, 2026
Jan 10, 2020
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
1Libming
1Libming
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.
1Jhead Project
1Jhead
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
1Jhead Project
1Jhead
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
1Nothings
1Stb Truetype.h
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
1Nothings
1Stb Truetype.h
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
1Nothings
1Stb Truetype.h
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
1Nothings
1Stb Truetype.h
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
1Google
1Android
Jun 17, 2026
Jan 8, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges need...Show more
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142558228Show less
4Canonical
DebianFreedesktop+1 more
4Debian Linux
LeapLibbsd+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
2Libsdl
Redhat
2Enterprise Linux
Simple Directmedia Layer
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-base...Show more
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.Show less
1Nasm
1Netwide Assembler
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.