← Back
CWE-125

9,119 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liblas
1Liblas
Nov 21, 2024
Dec 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loo...Show more
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.Show less
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input beca...Show more
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.Show less
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by craftin...Show more
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.Show less
1Libdoc Project
1Libdoc
Nov 21, 2024
Dec 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.
1Libdoc Project
1Libdoc
Nov 21, 2024
Dec 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.
2Debian
Gnu
2Debian Linux
Libextractor
Nov 21, 2024
Dec 24, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
1Axiosys
1Bento4
Nov 21, 2024
Dec 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by mp42hls.
2Canonical
Qemu
2Qemu
Ubuntu Linux
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.
1Google
1Android
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.
3Canonical
FedoraprojectFreerdp
3Fedora
FreerdpUbuntu Linux
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that...Show more
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.Show less
1Pur3
1Espruino
Nov 21, 2024
Dec 18, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.
3Canonical
DebianGraphicsmagick
3Debian Linux
GraphicsmagickUbuntu Linux
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image fi...Show more
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.Show less
1Virustotal
1Yara
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD.
3Canonical
HaproxyRedhat
3Haproxy
Openshift Container PlatformUbuntu Linux
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding t...Show more
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.Show less
1Siemens
5Sinumerik 808d V4.7 Firmware
Sinumerik 808d V4.8 FirmwareSinumerik 828d V4.7 Firmware+2 more
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINU...Show more
A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). A local attacker could use ioctl calls to do out of bounds reads, arbitrary writes, or execute code in kernel mode. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Exiv2
1Exiv2
Nov 21, 2024
Dec 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
1Exiv2
1Exiv2
Nov 21, 2024
Dec 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.