← Back
CWE-125

9,626 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Ytnef Project
2Debian Linux
Ytnef
May 13, 2026
Mar 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
1Pharos
1Popup
May 13, 2026
Mar 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to an out of bounds read...Show more
A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to an out of bounds read causing a crash and a denial of service.Show less
2Debian
Libtiff
2Debian Linux
Libtiff
May 13, 2026
Mar 7, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
2Debian
Freetype
2Debian Linux
Freetype
May 13, 2026
Mar 6, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or pos...Show more
The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
Mar 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.
2Imagemagick
Opensuse
2Imagemagick
Leap
May 13, 2026
Mar 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
3Fedoraproject
Libass ProjectOpensuse
4Fedora
LeapLibass+1 more
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
1Matrixssl
1Matrixssl
May 13, 2026
Mar 3, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
1Libimobiledevice
1Libplist
May 13, 2026
Mar 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
2Debian
Irssi
2Debian Linux
Irssi
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
1Irssi
1Irssi
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.
1Irssi
1Irssi
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
1Radare
1Radare2
May 13, 2026
Mar 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
1Linux
1Linux Kernel
May 13, 2026
Mar 1, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or...Show more
The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmission.Show less
1Gdraheim
1Zziplib
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ZIP file.
1Gdraheim
1Zziplib
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted ZIP file.
1Jasper Project
1Jasper
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
1Iceni
1Argus
May 13, 2026
Feb 28, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will explicitly trust an index within the specific font object and use it to write t...Show more
An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will explicitly trust an index within the specific font object and use it to write the font's name to a single object within an array of objects.Show less
1Qemu
1Qemu
May 13, 2026
Feb 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout...Show more
The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIO_GPU_CMD_SET_SCANOUT command larger than num_scanouts.Show less