← Back
CWE-125

9,120 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Uvnc
1Ultravnc
Jun 17, 2026
Mar 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be expl...Show more
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1208.Show less
1Uvnc
1Ultravnc
Jun 17, 2026
Mar 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vuln...Show more
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.Show less
3Debian
FedoraprojectFreedesktop
3Debian Linux
FedoraPoppler
Jun 17, 2026
Mar 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
5Debian
FedoraprojectLibjpeg Turbo+2 more
5Debian Linux
FedoraLeap+2 more
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or...Show more
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
Jun 17, 2026
Mar 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use...Show more
A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.Show less
1Moxa
4Eds 405a Firmware
Eds 408a FirmwareEds 510a Firmware+1 more
Jun 17, 2026
Mar 5, 2019
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot.
1Apple
4Iphone Os
Mac Os XTvos+1 more
Jun 17, 2026
Mar 5, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
1Apple
3Iphone Os
ItunesMac Os X
Jun 17, 2026
Mar 5, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.
1Apple
1Mac Os X
Jun 17, 2026
Mar 5, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.3. An application may be able to read restricted memory.
1Apple
4Iphone Os
Mac Os XTv Os+1 more
Jun 17, 2026
Mar 5, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A m...Show more
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout.Show less
1Apple
3Iphone Os
Mac Os XWatchos
Jun 17, 2026
Mar 5, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges.
1Apple
2Iphone Os
Mac Os X
Jun 17, 2026
Mar 5, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.
1Uvnc
1Ultravnc
Jun 17, 2026
Mar 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability...Show more
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.Show less
1Uvnc
1Ultravnc
Jun 17, 2026
Mar 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been...Show more
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.Show less
1Deltaww
1Screeneditor
Jun 17, 2026
Feb 28, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files.
1Google
1Android
Jun 17, 2026
Feb 28, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges ne...Show more
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-111451066.Show less
4Advancemame
CanonicalDebian+1 more
4Advancecomp
Debian LinuxFedora+1 more
Jun 17, 2026
Feb 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-b...Show more
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)Show less
4Canonical
GnuMcafee+1 more
6Cloud Backup
GlibcOntap Select Deploy Administration Utility+3 more
Jun 17, 2026
Feb 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
1Hdfgroup
1Hdf5
Jun 17, 2026
Feb 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H5MM.c when called from H5O_dtype_decode_helper in H5Odtype.c.
1Hdfgroup
1Hdf5
Jun 17, 2026
Feb 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in H5VM.c when called from H5D__compact_readvv in H5Dcompact.c.