← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libsass
1Libsass
May 13, 2026
Jun 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.
1Mpg123
1Mpg123
May 13, 2026
Jun 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
1Linux
1Linux Kernel
May 13, 2026
Jun 28, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of...Show more
The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
May 13, 2026
Jun 28, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by ch...Show more
The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.Show less
1Linux
1Linux Kernel
May 13, 2026
Jun 28, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by cha...Show more
The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.Show less
1Openvpn
1Openvpn
May 13, 2026
Jun 27, 2017
N/A· v4
7.4 HIGH· v3
4.0 MEDIUM· v2
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 f...Show more
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.Show less
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 f...Show more
The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.Show less
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 f...Show more
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.Show less
1Gnu
1Binutils
May 13, 2026
Jun 26, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and a...Show more
The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file in which a certain size field is larger than a corresponding data field, as demonstrated by mishandling within the objdump program.Show less
1Gnu
1Binutils
May 13, 2026
Jun 26, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and appl...Show more
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex file, as demonstrated by mishandling within the nm program.Show less
2Libtiff
Opensuse
2Libtiff
Opensuse
May 13, 2026
Jun 26, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig fu...Show more
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.Show less
3Canonical
DebianLibtiff
3Debian Linux
LibtiffUbuntu Linux
May 13, 2026
Jun 26, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bo...Show more
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invalid free in TIFFClose or t2p_free, memory corruption in t2p_readwrite_pdf_image, or a double free in t2p_free. Given these possibilities, it probably could cause arbitrary code execution.Show less
1Lame Project
1Lame
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted a...Show more
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type == 2" case, a similar issue to CVE-2017-11126.Show less
1Lame Project
1Lame
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted au...Show more
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.Show less
1Lame Project
1Lame
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to mis...Show more
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.Show less
1Libtorrent
1Libtorrent
May 13, 2026
Jun 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
1Jasper Project
1Jasper
May 13, 2026
Jun 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.
1Freeware Advanced Audio Coder Project
1Freeware Advanced Audio Coder
May 13, 2026
Jun 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.