← Back
CWE-125

9,626 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Radare
1Radare2
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
1Adobe
1Flash Player
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of the APP13 segment in JP...Show more
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of the APP13 segment in JPEG files.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of EMF - enhanced meta fil...Show more
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of EMF - enhanced meta file format.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of JPEG files....Show more
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of JPEG files. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to contiguous code-stream parsing.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when handling JPEG 2000 code-stream tile data.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 code-stream parser.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the XSLT engine.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser engine.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the Product Representation Compact (PRC) format parser. Success...Show more
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the Product Representation Compact (PRC) format parser. Successful exploitation could lead to arbitrary code execution.Show less
2Debian
Libsamplerate Project
2Debian Linux
Libsamplerate
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attackers to cause a denial of service (crash) via a crafted png file.
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
The JPEG decoder in ImageMagick before 6.8.9-9 allows local users to cause a denial of service (out-of-bounds memory access and crash).
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
1Imagemagick
1Imagemagick
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The HorizontalFilter function in resize.c in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
2Debian
Libtiff
2Debian Linux
Libtiff
May 13, 2026
Apr 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.