CWE-125
9,090 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,090)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure. |
1Long Range Zip Project 1Long Range Zip May 13, 2026 May 8, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 May 8, 2017 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other i...Show more |
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly...Show more |
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfMay 13, 2026 May 3, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document. |
1Foxitsoftware 2Foxit Reader PhantompdfMay 13, 2026 May 3, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document. |
1Foxitsoftware 2Foxit Reader PhantompdfMay 13, 2026 May 3, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document. |
2Debian Rxvt Project2Debian Linux RxvtMay 13, 2026 May 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read...Show more |
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this...Show more |
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT...Show more |
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. |
2Debian Libsndfile Project2Debian Linux LibsndfileMay 13, 2026 Apr 30, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. |
2Debian Libsndfile Project2Debian Linux LibsndfileMay 13, 2026 Apr 30, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. |
2Debian Libsndfile Project2Debian Linux LibsndfileMay 13, 2026 Apr 30, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file. |
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreApr 21, 2026 Apr 24, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page. |
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a ra...Show more |
1Lexmark 1Perceptive Document Filters May 13, 2026 Apr 20, 2017 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulner...Show more |
The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file. |