← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
X.org
2Fedora
Libxv
May 6, 2026
Dec 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received dat...Show more
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.Show less
1Imagemagick
1Imagemagick
May 6, 2026
Dec 13, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.
2Imagemagick
Oracle
2Imagemagick
Solaris
May 6, 2026
Dec 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and cra...Show more
Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.Show less
2Imagemagick
Oracle
2Imagemagick
Solaris
May 6, 2026
Dec 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
2Imagemagick
Oracle
2Imagemagick
Solaris
May 6, 2026
Dec 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.
1Tats
1W3m
May 6, 2026
Dec 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds array access) via a crafted HTML page.
1Bluez Project
1Bluez
May 6, 2026
Dec 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
1Bluez
1Bluez
May 6, 2026
Dec 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array...Show more
In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.Show less
1Bluez
1Bluez
May 6, 2026
Dec 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access...Show more
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.Show less
1Libtiff
1Libtiff
May 6, 2026
Nov 22, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.
1Linux
1Linux Kernel
May 6, 2026
Nov 16, 2016
N/A· v4
5.0 MEDIUM· v3
4.3 MEDIUM· v2
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information...Show more
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.Show less
1Linux
1Linux Kernel
May 6, 2026
Nov 16, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds r...Show more
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.Show less
1Linux
1Linux Kernel
May 6, 2026
Nov 16, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memor...Show more
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.Show less
1Foxitsoftware
2Phantompdf
Reader
May 6, 2026
Oct 31, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream...Show more
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."Show less
1Foxitsoftware
2Phantompdf
Reader
May 6, 2026
Oct 31, 2016
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream...Show more
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."Show less
1Foxitsoftware
2Phantompdf
Reader
May 6, 2026
Oct 31, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted...Show more
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."Show less
1Artifex
1Mujs
May 6, 2026
Oct 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploitation of this issue can lead to code exec...Show more
An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploitation of this issue can lead to code execution or denial of service condition.Show less
1Artifex
1Mujs
May 6, 2026
Oct 28, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out...Show more
Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.Show less
2Libgd
Opensuse
3Leap
LibgdOpensuse
May 6, 2026
Oct 3, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.