← Back
CWE-125

9,626 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libtiff
1Libtiff
May 6, 2026
Oct 3, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
1Libtiff
1Libtiff
May 6, 2026
Oct 3, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.
1Libtiff
1Libtiff
May 6, 2026
Oct 3, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.
1Libtiff
1Libtiff
May 6, 2026
Oct 3, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BM...Show more
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.Show less
6Canonical
DebianHp+3 more
9Debian Linux
Icewall Federation AgentIcewall Mcrp+6 more
May 6, 2026
Sep 26, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted ap...Show more
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted ap...Show more
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4776.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted ap...Show more
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4774 and CVE-2016-4776.Show less
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "displa...Show more
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.Show less
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer...Show more
The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.Show less
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
1Libarchive
1Libarchive
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, relate...Show more
The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.Show less
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
3Canonical
LibarchiveNovell
5Libarchive
Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
3Canonical
LibarchiveNovell
5Libarchive
Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
3Canonical
LibarchiveNovell
5Libarchive
Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
1Libarchive
1Libarchive
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
1Wireshark
1Wireshark
May 6, 2026
Sep 9, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) v...Show more
epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.Show less
1Gnu
1Libidn
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.