CWE-125
9,091 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,091)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Foxitsoftware 1Foxit Reader May 13, 2026 Dec 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must vis...Show more |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 20, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation. |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Dec 18, 2017 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c an...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Dec 13, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack. |
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file. |
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Dec 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file. |
2Adobe Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreMay 13, 2026 Dec 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of...Show more |
2Adobe Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreMay 13, 2026 Dec 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 13, 2026 Dec 9, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occ...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 13, 2026 Dec 9, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occ...Show more |