← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Apr 21, 2026
Jan 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary re...Show more
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.Show less
1Libtiff
1Libtiff
May 13, 2026
Jan 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.
1Libtiff
1Libtiff
May 13, 2026
Jan 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
1Artifex
1Mujs
May 13, 2026
Jan 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
Jan 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
1Artifex
1Mujs
May 13, 2026
Jan 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.
1Imagemagick
1Imagemagick
May 13, 2026
Jan 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
1Gstreamer
1Gstreamer
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.
4Debian
FedoraprojectGstreamer+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+6 more
May 13, 2026
Jan 13, 2017
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
1Gstreamer
1Gstreamer
May 13, 2026
Jan 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, w...Show more
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.Show less
1Gstreamer
1Gstreamer
May 13, 2026
Jan 13, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.
1Gstreamer
1Gstreamer
May 13, 2026
Jan 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
1Libimobiledevice
1Libplist
May 6, 2026
Jan 11, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple...Show more
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.Show less
1Foxitsoftware
1Reader
May 6, 2026
Jan 6, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information disclosure. Combined with another vulnerability, it can be used to leak heap memory layout and in bypassi...Show more
A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information disclosure. Combined with another vulnerability, it can be used to leak heap memory layout and in bypassing ASLR.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
3.1 LOW· v3
4.3 MEDIUM· v2
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular...Show more
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disc...Show more
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can s...Show more
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
5.9 MEDIUM· v3
4.9 MEDIUM· v2
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle...Show more
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-th...Show more
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability.Show less