← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The HorizontalFilter function in resize.c in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
2Debian
Libtiff
2Debian Linux
Libtiff
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
1Entropymine
1Imageworsener
May 13, 2026
Apr 10, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
3Canonical
DebianElfutils Project
3Debian Linux
ElfutilsUbuntu Linux
May 13, 2026
Apr 9, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
3Canonical
DebianElfutils Project
3Debian Linux
ElfutilsUbuntu Linux
May 13, 2026
Apr 9, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
3Canonical
DebianElfutils Project
3Debian Linux
ElfutilsUbuntu Linux
May 13, 2026
Apr 9, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
3Canonical
DebianElfutils Project
3Debian Linux
ElfutilsUbuntu Linux
May 13, 2026
Apr 9, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
1Elfutils Project
1Elfutils
May 13, 2026
Apr 9, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
1Entropymine
1Imageworsener
May 13, 2026
Apr 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/sun.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted sun file.
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function in PdfEncoding.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF docu...Show more
The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function in PdfEncoding.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document.Show less
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The PoDoFo::PdfPainter::ExpandTabs function in PdfPainter.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document.
1Virustotal
1Yara
May 13, 2026
Apr 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function.
1Apple
1Safari
May 13, 2026
Apr 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that...Show more
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorString function, related to assembler/MacroAssemblerARM64.h, assembler/MacroAssemblerX86Common.h, and wasm/WasmB3IRGenerator.cpp.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Apr 2, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component....Show more
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font file.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Apr 2, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" componen...Show more
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font file.Show less
1Apple
1Mac Os X
May 13, 2026
Apr 2, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Menus" component. It allows attackers to obtain sensitive information or cause a denial of service (out-of-boun...Show more
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Menus" component. It allows attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted app.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Mar 31, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to inform...Show more
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.Show less