← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libav
1Libav
May 13, 2026
Mar 21, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 vid...Show more
The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.Show less
1Audiofile
1Audiofile
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
1Virglrenderer Project
1Virglrenderer
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
1Gnu
1Glibc
May 13, 2026
Mar 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds...Show more
The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.Show less
5Canonical
ImagemagickOpensuse+2 more
10Imagemagick
LeapOpensuse+7 more
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
1Gnu
1Binutils
May 13, 2026
Mar 17, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Mar 16, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary c...Show more
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length.Show less
2Fedoraproject
Netpbm Project
2Fedora
Netpbm
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related...Show more
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file.
1Ettercap Project
1Ettercap
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted filter.
2Debian
Libevent Project
2Debian Linux
Libevent
May 13, 2026
Mar 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
2Debian
Libevent Project
2Debian Linux
Libevent
May 13, 2026
Mar 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
1Jasper Project
1Jasper
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
1Podofo Project
1Podofo
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) via a crafted file.
1Libplist Project
1Libplist
May 13, 2026
Mar 15, 2017
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.
1Libgd
1Libgd
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression b...Show more
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.Show less
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Mar 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value i...Show more
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.Show less
1Wavpack Project
1Wavpack
May 13, 2026
Mar 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
1Wavpack Project
1Wavpack
May 13, 2026
Mar 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
1Wavpack Project
1Wavpack
May 13, 2026
Mar 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.