CWE-125— Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
9,453 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-125page 19 of 190
- CVE-2017-7379MEDIUMCVSS 5.5EG 5.52017-04-03
The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function in PdfEncoding.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document.
- CVE-2017-7454MEDIUMCVSS 5.5EG 5.52017-04-06
The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
- CVE-2017-7483HIGHCVSS 7.5EG 7.52017-05-02
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
- CVE-2017-7520HIGHCVSS 7.4EG 7.42017-06-27
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
- CVE-2017-7544CRITICALCVSS 9.1EG 9.12017-09-21
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause de…
- CVE-2017-7558HIGHCVSS 5.1EG 7.52018-07-26
A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functio…
- CVE-2017-7607MEDIUMCVSS 5.5EG 5.52017-04-09
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
- CVE-2017-7608MEDIUMCVSS 5.5EG 5.52017-04-09
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
- CVE-2017-7610MEDIUMCVSS 5.5EG 5.52017-04-09
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
- CVE-2017-7611MEDIUMCVSS 5.5EG 5.52017-04-09
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
- CVE-2017-7612MEDIUMCVSS 5.5EG 5.52017-04-09
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
- CVE-2017-7623MEDIUMCVSS 5.5EG 5.52017-04-10
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
- CVE-2017-7668HIGHCVSS 7.5EG 8.22017-06-20
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers,…
- CVE-2017-7697MEDIUMCVSS 5.5EG 5.52017-04-11
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
- CVE-2017-7716MEDIUMCVSS 5.5EG 5.52017-04-12
The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
- CVE-2017-7718MEDIUMCVSS 5.5EG 5.52017-04-20
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_…
- CVE-2017-7753CRITICALCVSS 9.1EG 9.12018-06-11
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- CVE-2017-7754HIGHCVSS 7.5EG 7.52018-06-11
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
- CVE-2017-7758CRITICALCVSS 9.1EG 9.12018-06-11
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
- CVE-2017-7771HIGHCVSS 8.1EG 8.12019-04-15
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
- CVE-2017-7774CRITICALCVSS 9.1EG 9.12019-04-15
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
- CVE-2017-7776HIGHCVSS 8.1EG 8.12019-04-15
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
- CVE-2017-7778CRITICALCVSS 9.8EG 9.82018-06-11
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerabili…
- CVE-2017-7813HIGHCVSS 8.2EG 8.22018-06-11
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory i…
- CVE-2017-7854MEDIUMCVSS 5.5EG 5.52017-04-13
The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
- CVE-2017-7939MEDIUMCVSS 5.5EG 5.52017-04-18
The read_next_pam_token function in imagew-pnm.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted file.
- CVE-2017-7960MEDIUMCVSS 5.5EG 5.52017-04-19
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
- CVE-2017-8163MEDIUMCVSS 6.5EG 6.52017-11-22
AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R0…
- CVE-2017-8182MEDIUMCVSS 6.1EG 6.12017-11-22
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on…
- CVE-2017-8199MEDIUMCVSS 6.5EG 6.52017-11-22
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an out-of-bounds read vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient …
- CVE-2017-8200MEDIUMCVSS 6.5EG 6.52017-11-22
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an out-of-bounds read vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient …
- CVE-2017-8234HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.
- CVE-2017-8240HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.
- CVE-2017-8256HIGHCVSS 7.8EG 7.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 multicast addresses.
- CVE-2017-8258MEDIUMCVSS 5.5EG 5.52017-08-11
An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.
- CVE-2017-8268HIGHCVSS 7.8EG 7.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer processing with invalid values leading to the driver performing a heap buffer over-read.
- CVE-2017-8294HIGHCVSS 7.5EG 7.52017-04-27
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.
- CVE-2017-8310MEDIUMCVSS 5.5EG 5.52017-05-23
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a craft…
- CVE-2017-8312MEDIUMCVSS 5.5EG 5.52017-05-23
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
- CVE-2017-8313MEDIUMCVSS 5.5EG 5.52017-05-23
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
- CVE-2017-8362MEDIUMCVSS 6.5EG 6.52017-04-30
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
- CVE-2017-8363MEDIUMCVSS 6.5EG 6.52017-04-30
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
- CVE-2017-8365MEDIUMCVSS 6.5EG 6.52017-04-30
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
- CVE-2017-8374MEDIUMCVSS 5.5EG 5.52017-05-01
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
- CVE-2017-8393HIGHCVSS 7.5EG 7.52017-05-01
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA secti…
- CVE-2017-8401MEDIUMCVSS 6.5EG 6.52017-05-01
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS.
- CVE-2017-8453HIGHCVSS 8.8EG 8.82017-05-03
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
- CVE-2017-8454HIGHCVSS 8.8EG 8.82017-05-03
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
- CVE-2017-8455HIGHCVSS 7.8EG 7.82017-05-03
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
- CVE-2017-8787HIGHCVSS 8.8EG 8.82017-05-05
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified o…
Map vulnerabilities like CWE-125 to your infrastructure
EchelonGraph correlates every CVE — across CWE-125 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →