← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Fedoraproject
Libgit2 ProjectOpensuse+1 more
5Fedora
LeapLibgit2+2 more
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
1Gnome
1Librsvg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
1Libavformat Project
1Libavformat
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
1Lepton Project
1Lepton
May 13, 2026
Feb 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.
1Lepton Project
1Lepton
May 13, 2026
Feb 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.
1Pacman Project
1Pacman
May 13, 2026
Jan 30, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file.
7Debian
FreebsdNetapp+4 more
17Clustered Data Ontap
Communications User Data RepositoryData Ontap+14 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
1Libarchive
1Libarchive
May 13, 2026
Jan 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specia...Show more
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.Show less
1Libical Project
1Libical
May 13, 2026
Jan 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.
1Libical Project
1Libical
May 13, 2026
Jan 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The parser_get_next_char function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) by crafting a string to the icalparser_parse_string function.
1Libical Project
1Libical
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The icalparser_parse_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ics file.
1Aerospike
1Database Server
May 13, 2026
Jan 26, 2017
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
An exploitable out-of-bounds read vulnerability exists in the client message-parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an out-of-bounds read resulting in disclosure...Show more
An exploitable out-of-bounds read vulnerability exists in the client message-parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an out-of-bounds read resulting in disclosure of memory within the process, the same vulnerability can also be used to trigger a denial of service. An attacker can simply connect to the port and send the packet to trigger this vulnerability.Show less
1Libgd
1Libgd
May 13, 2026
Jan 26, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
1Php
1Php
May 13, 2026
Jan 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application cras...Show more
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call.Show less
2Gstreamer
Gstreamer Project
2Gstreamer
Gstreamer
May 13, 2026
Jan 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
1Libdwarf Project
1Libdwarf
May 13, 2026
Jan 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.
1Libtiff
1Libtiff
May 13, 2026
Jan 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.
1Foxitsoftware
2Foxit Reader
Phantompdf
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via...Show more
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.Show less
1Libimobiledevice
1Libplist
May 13, 2026
Jan 21, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data...Show more
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.Show less
3Libtiff
OpensuseOpensuse Project
3Leap
LibtiffOpensuse
May 13, 2026
Jan 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.