← Back
CWE-125

9,126 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,126)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianOpensuse+1 more
5Backports Sle
Debian LinuxLeap+2 more
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
1Comodo
1Antivirus
Jun 17, 2026
Jul 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and conta...Show more
Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object data causing CmdAgent.exe to crash.Show less
4Debian
FedoraprojectLibsdl+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
5Debian
F5Fedoraproject+2 more
7Cloud Backup
Debian LinuxE Series Santricity Os Controller+4 more
Jun 17, 2026
Jul 16, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attack...Show more
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.Show less
1Gpac
1Gpac
Jun 17, 2026
Jul 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
1F5
1Njs
Jun 17, 2026
Jul 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call a...Show more
njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.Show less
6Canonical
DebianFedoraproject+3 more
13Backports Sle
Debian LinuxEnterprise Linux+10 more
Jun 17, 2026
Jul 16, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
1Videolan
1Vlc Media Player
Jun 17, 2026
Jul 16, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
2Linaro
Trustedfirmware
2Op Tee
Op Tee
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.
1Sound Exchange Project
1Sound Exchange
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted...Show more
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode det...Show more
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decoding the string. There are no checks to ensure that the length it calculates isn't greater than the input buffer. This leads to adjacent memory being decoded as well. An attacker would not be able to retrieve the decoded data unless the Squid maintainer had configured the display of usernames on error pages.Show less
2Debian
Exiv2
2Debian Linux
Exiv2
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
1Cesanta
1Mongoose
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
1Matrixssl
1Matrixssl
Jun 17, 2026
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
1Google
1Android
Jun 17, 2026
Jul 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction...Show more
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-117105007.Show less
1Imagemagick
1Imagemagick
Jun 17, 2026
Jul 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.
1Ffmpeg
1Ffmpeg
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.
2Imagemagick
Opensuse
2Imagemagick
Leap
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.
2Imagemagick
Opensuse
2Imagemagick
Leap
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.
2Imagemagick
Opensuse
2Imagemagick
Leap
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.