← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Artifex
1Ghostscript Ghostxps
May 13, 2026
Jul 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspec...Show more
The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document, related to the xps_encode_font_char_imp function.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
May 13, 2026
Jul 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other im...Show more
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.Show less
1Artifex
1Ghostscript Ghostxps
May 13, 2026
Jul 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified...Show more
The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.Show less
1Sipcrack Project
1Sipcrack
May 13, 2026
Jul 26, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sip...Show more
An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Jul 26, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accesso...Show more
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Jul 25, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.
1Libsass
1Libsass
May 13, 2026
Jul 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
1Libsass
1Libsass
May 13, 2026
Jul 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.
1Linux
1Linux Kernel
May 13, 2026
Jul 24, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a den...Show more
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.Show less
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
1Fontforge
1Fontforge
May 13, 2026
Jul 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.
1Tcpdump
1Tcpdump
May 13, 2026
Jul 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.
1Tcpdump
1Tcpdump
May 13, 2026
Jul 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called from the WritePICONImage function in coders/xpm.c.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WritePSImage() function in coders/ps.c.