← Back
CWE-125

9,120 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GraphicsmagickOpensuse
3Debian Linux
GraphicsmagickLeap
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.Show less
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
1Oisf
1Libhtp
Nov 21, 2024
Apr 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
2Debian
Oisf
2Debian Linux
Suricata
Nov 21, 2024
Apr 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check...Show more
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.2.
1Apple
4Iphone Os
Mac Os XTvos+1 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12.1.
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to macOS Mojave 10.14.
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to macOS High Sierra 10.13.6.
1Apple
3Iphone Os
TvosWatchos
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2.
1Apple
4Iphone Os
Mac Os XTvos+1 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
1Apple
4Iphone Os
Mac Os XTvos+1 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
1Imagemagick
1Imagemagick
Jun 17, 2026
Apr 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.
1Vmware
3Esxi
FusionWorkstation
Jun 17, 2026
Apr 1, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out...Show more
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.Show less
1Long Range Zip Project
1Long Range Zip
Jun 17, 2026
Mar 30, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archi...Show more
The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image fil...Show more
In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file.Show less
1We Con
2Pi Studio
Pi Studio Hmi
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which may result in a read past the end of an allocated object.
1Laquisscada
1Laquis Scada
Nov 21, 2024
Mar 27, 2019
N/A· v4
7.1 HIGH· v3
7.8 HIGH· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system crash or allow data exfiltration.
1Rockwellautomation
1Rslinx Enterprise
Nov 21, 2024
Mar 26, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receive...Show more
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receives a datagram with an incorrect value in the “Record Data Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to an oversized value, an attacker could cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to this vulnerability can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599Show less