← Back
CWE-125

9,102 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,102)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Nov 21, 2024
Apr 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app()...Show more
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app() is invoked without validating the packet length. If the packet length is invalid, then a buffer over-read can occur.Show less
1Google
1Android
Nov 21, 2024
Apr 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_...Show more
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_OFFSET is not defined which can lead to a buffer over-read in nla_get_u32().Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of s...Show more
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of s...Show more
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.Show less
1Nvidia
1Gpu Driver
Jun 17, 2026
Apr 2, 2018
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential operation to read or write a buffer, but it uses an incorrect length valu...Show more
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service or possible escalation of privileges.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Apr 2, 2018
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image because balloc.c a...Show more
The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image because balloc.c and ialloc.c do not validate bitmap block numbers.Show less
1Exiv2
1Exiv2
Jun 17, 2026
Mar 30, 2018
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.
1Imagemagick
1Imagemagick
Jun 17, 2026
Mar 30, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.
3Canonical
ClamavDebian
3Clamav
Debian LinuxUbuntu Linux
Nov 21, 2024
Mar 27, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper inpu...Show more
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.Show less
4Apache
CanonicalDebian+1 more
7Clustered Data Ontap
Debian LinuxHttp Server+4 more
Nov 21, 2024
Mar 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Se...Show more
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.Show less
3Debian
Exiv2Redhat
5Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+2 more
Jun 17, 2026
Mar 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
1Netpbm Project
1Netpbm
Jun 17, 2026
Mar 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
2Canonical
Imagemagick
2Imagemagick
Ubuntu Linux
Jun 17, 2026
Mar 23, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer over-read.
1Libav
1Libav
Nov 21, 2024
Mar 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted media file.
1Libav
1Libav
Nov 21, 2024
Mar 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted audio file.
1Libav
1Libav
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file, related to ff_ps_apply.
1Libav
1Libav
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.
1Nasm
1Netwide Assembler
Jun 17, 2026
Mar 20, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.
2Canonical
Nasm
2Netwide Assembler
Ubuntu Linux
Jun 17, 2026
Mar 20, 2018
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
2Deadwood Project
Maradns Project
2Deadwood
Maradns
Nov 21, 2024
Mar 20, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perfor...Show more
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation.Show less