← Back
CWE-125

9,121 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,121)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mqtt Packet Project
1Mqtt Packet
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.
2Debian
Dhcpcd Project
2Debian Linux
Dhcpcd
Jun 17, 2026
May 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
May 3, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.Show less
1Gnu
1Recutils
Jun 17, 2026
May 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.
1Gnu
1Recutils
Jun 17, 2026
May 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.
1Facebook
1Hhvm
Jun 17, 2026
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
1Imagemagick
1Imagemagick
Jun 17, 2026
Apr 29, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted im...Show more
In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file. This is related to SetGrayscaleImage in MagickCore/quantize.c.Show less
1Imagemagick
1Imagemagick
Jun 17, 2026
Apr 29, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted...Show more
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.Show less
1Davegamble
1Cjson
Jul 22, 2025
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
2Debian
Dhcpcd Project
2Debian Linux
Dhcpcd
Jun 17, 2026
Apr 28, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
1Mozilla
1Firefox
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitra...Show more
If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrome process, which may include sensitive data. This vulnerability affects Firefox < 66.Show less
1Mozilla
1Firefox
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Fir...Show more
Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.Show less
-
-
Nov 7, 2023
Apr 24, 2019
N/A· v4
N/A· v3
N/A· v2
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7576, CVE-2018-21233. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues....Show more
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7576, CVE-2018-21233. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2018-7576 and CVE-2018-21233 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usageShow less
1Graphicsmagick
1Graphicsmagick
Jun 17, 2026
Apr 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-110...Show more
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraMonit+1 more
Jun 17, 2026
Apr 22, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker...Show more
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).Show less
2Fedoraproject
Mediaarea
2Fedora
Mediainfo
Jun 17, 2026
Apr 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
2Fedoraproject
Mediaarea
2Fedora
Mediainfo
Jun 17, 2026
Apr 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
1Google
1Android
Jun 17, 2026
Apr 19, 2019
N/A· v4
5.0 MEDIUM· v3
4.7 MEDIUM· v2
In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User inter...Show more
In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122316913.Show less
1Google
1Android
Jun 17, 2026
Apr 19, 2019
N/A· v4
5.0 MEDIUM· v3
4.7 MEDIUM· v2
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction...Show more
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-121260197.Show less
1Google
1Android
Jun 17, 2026
Apr 19, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interacti...Show more
In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-121259048.Show less