CWE-125
9,126 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,126)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged l...Show more |
An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl->phys out-of-bounds read. |
In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, the emulated XHCI device included wit...Show more |
1Qualcomm 36Msm8909w Firmware Msm8996au FirmwareQcs605 Firmware+33 moreJun 17, 2026 Jul 25, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Out of bound read and information disclosure in firmware due to insufficient checking of an embedded structure that can be sent from a kernel driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr...Show more |
1Qualcomm 39Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+36 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snap...Show more |
1Qualcomm 40Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+37 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mo...Show more |
1Qualcomm 36Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+33 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Out of bound access when reason code is extracted from frame data without validating the frame length in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Qualcomm 24Ipq4019 Firmware Ipq8064 FirmwareMsm8909w Firmware+21 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Possibility of out-of-bound read if id received from SPI is not in range of FIFO in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdr...Show more |
1Qualcomm 22Mdm9607 Firmware Msm8996au FirmwareQca6174a Firmware+19 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon...Show more |
1Qualcomm 30Msm8909w Firmware Qcs605 FirmwareQualcomm 215 Firmware+27 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snap...Show more |
1Qualcomm 43Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+40 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer over-read can occur while parsing an ogg file with a corrupted comment block. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Sna...Show more |
1Deltaww 1Cnssoft Screeneditor Jun 17, 2026 Jul 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files. |
mgetty prior to 1.2.1 is affected by: out-of-bounds read. The impact is: DoS, the program may crash if the memory is not mapped. The component is: putwhitespan() in g3/pbm2g3.c. The attack vector is: Local, the victim mu...Show more |
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector...Show more |
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure....Show more |
2Gnu Netapp4Binutils Binutils GoldHci Management Node+1 moreJun 17, 2026 Jul 23, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread...Show more |
Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read. The impact is: denial of service. The component is: function lexer_getchar (jsiLexer.c:9). The attack vector is: executing crafted javascript code. The fixed versio...Show more |
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function nam...Show more |
1Qualcomm 28Msm8996au Firmware Qcs405 FirmwareQcs605 Firmware+25 moreJun 17, 2026 Jul 22, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Out of bound read can happen due to lack of NULL termination on user controlled data in WLAN in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice...Show more |
Adobe Bridge CC version 9.0.2 and earlier versions have an out of bound read vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. |