← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autotrace Project
1Autotrace
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:17:11.
1Autotrace Project
1Autotrace
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11.
1Autotrace Project
1Autotrace
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the input_pnm_reader function in input-pnm.c:243:3.
1Autotrace Project
1Autotrace
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:16:11.
1Autotrace Project
1Autotrace
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the pnm_load_raw function in input-pnm.c:346:41.
1Libtiff
1Libtiff
May 13, 2026
May 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
2Canonical
Libtiff
2Libtiff
Ubuntu Linux
May 13, 2026
May 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer o...Show more
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).Show less
1Linux
1Linux Kernel
May 13, 2026
May 19, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bo...Show more
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.Show less
2Canonical
Ytnef Project
2Ubuntu Linux
Ytnef
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
1Libdwarf Project
1Libdwarf
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.
1Libdwarf Project
1Libdwarf
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to a heap-based buffer...Show more
An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to a heap-based buffer over-read.Show less
1Libdwarf Project
1Libdwarf
May 13, 2026
May 18, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in a few places in this...Show more
An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in a few places in this function).Show less
1Libdwarf Project
1Libdwarf
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few places in this function...Show more
An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few places in this function) and a failure in a check in dwarf_attr_list().Show less
1Xmlsoft
1Libxml2
May 13, 2026
May 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerabilit...Show more
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.Show less
1Xmlsoft
1Libxml2
May 13, 2026
May 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnera...Show more
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.Show less
1Gnu
1Binutils
May 13, 2026
May 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
1Gnu
1Binutils
May 13, 2026
May 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in...Show more
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c.Show less
1Gnu
1Binutils
May 13, 2026
May 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwi...Show more
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets.Show less
1Cisco
1Sourcefire Snort
May 13, 2026
May 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing t...Show more
Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing the array size solves this problem.Show less
1Artifex
1Ghostscript
May 13, 2026
May 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.