← Back
CWE-125

9,626 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in coders/hdr.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted HDR file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadSUNImage function in coders/sun.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SUN file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The EncodeImage function in coders/pict.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PICT file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted VIFF file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadPSDChannelPixels function in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/tiff.c in ImageMagick before 6.9.5-3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted SUN file.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cir...Show more
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.Show less
1Gnome
1Libcroco
May 13, 2026
Apr 19, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadWPGImage function in coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WPG file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/xcf.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted XCF file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted VIFF file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
1Entropymine
1Imageworsener
May 13, 2026
Apr 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_next_pam_token function in imagew-pnm.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted file.
2Broadcom
Symantec
15Advanced Threat Protection
CsapiEmail Security.cloud+12 more
May 13, 2026
Apr 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (...Show more
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted RAR file that is mishandled during decompression.Show less
1Radare
1Radare2
May 13, 2026
Apr 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.