← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xmlsoft
1Libxml2
May 13, 2026
May 10, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
1Long Range Zip Project
1Long Range Zip
May 13, 2026
May 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 13, 2026
May 8, 2017
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other i...Show more
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "double fetch" vulnerability.Show less
1Podofo Project
1Podofo
May 13, 2026
May 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly...Show more
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted PDF file.Show less
2Nodejs
Openssl
2Node.js
Openssl
May 13, 2026
May 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For...Show more
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.Show less
1Foxitsoftware
2Foxit Reader
Phantompdf
May 13, 2026
May 3, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
1Foxitsoftware
2Foxit Reader
Phantompdf
May 13, 2026
May 3, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
1Foxitsoftware
2Foxit Reader
Phantompdf
May 13, 2026
May 3, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
2Debian
Rxvt Project
2Debian Linux
Rxvt
May 13, 2026
May 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read...Show more
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.Show less
1Swftools
1Swftools
May 13, 2026
May 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this...Show more
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS.Show less
1Gnu
1Binutils
May 13, 2026
May 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always named starting with a .rel/.rela prefix. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objcopy and strip, to crash.Show less
1Underbit
1Mad Libmad
May 13, 2026
May 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
2Debian
Libsndfile Project
2Debian Linux
Libsndfile
May 13, 2026
Apr 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
2Debian
Libsndfile Project
2Debian Linux
Libsndfile
May 13, 2026
Apr 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
2Debian
Libsndfile Project
2Debian Linux
Libsndfile
May 13, 2026
Apr 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
1Virustotal
1Yara
May 13, 2026
Apr 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Apr 21, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
1Cisco
1Ios Xe
May 13, 2026
Apr 20, 2017
N/A· v4
6.3 MEDIUM· v3
6.3 MEDIUM· v2
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a ra...Show more
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when the affected software processes an SNMP read request that contains certain criteria for a specific object ID (OID) and an active crypto session is disconnected on an affected device. An attacker who can authenticate to an affected device could trigger this vulnerability by issuing an SNMP request for a specific OID on the device. A successful exploit will cause the device to restart due to an attempt to access an invalid memory region. The attacker does not control how or when crypto sessions are disconnected on the device. Cisco Bug IDs: CSCvb94392.Show less
1Lexmark
1Perceptive Document Filters
May 13, 2026
Apr 20, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulner...Show more
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400Show less
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file.