VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (2,466)

page 121 of 124
  • CVE-2018-7728MedMar 6, 2018
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

  • CVE-2018-7557MedFeb 28, 2018
    risk 0.00cvss 6.5epss 0.02

    The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.

  • CVE-2018-7253HigFeb 19, 2018
    risk 0.00cvss 7.8epss 0.03

    The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.

  • CVE-2017-18185MedFeb 13, 2018
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

  • CVE-2017-18184MedFeb 13, 2018
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

  • CVE-2018-6767HigFeb 6, 2018
    risk 0.00cvss 7.8epss 0.03

    A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.

  • CVE-2018-6621MedFeb 5, 2018
    risk 0.00cvss 6.5epss 0.02

    The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.

  • CVE-2018-6611HigFeb 4, 2018
    risk 0.00cvss 8.8epss 0.01

    soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.

  • CVE-2017-16912MedJan 31, 2018
    risk 0.00cvss 5.9epss 0.04

    The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet.

  • CVE-2018-1000005CriJan 24, 2018
    risk 0.00cvss 9.1epss 0.05

    libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The…

  • CVE-2017-18009HigJan 1, 2018
    risk 0.00cvss 7.5epss 0.02

    In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.

  • CVE-2015-2697Nov 9, 2015
    risk 0.00cvss epss 0.04

    The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.

  • CVE-2014-9669Feb 8, 2015
    risk 0.00cvss epss 0.04

    Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.

  • CVE-2014-9658Feb 8, 2015
    risk 0.00cvss epss 0.05

    The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.

  • CVE-2014-9657Feb 8, 2015
    risk 0.00cvss epss 0.05

    The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.

  • CVE-2014-8483Nov 6, 2014
    risk 0.00cvss epss 0.04

    The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.

  • CVE-2014-3675Oct 22, 2014
    risk 0.00cvss epss 0.03

    Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

  • CVE-2014-4341Jul 20, 2014
    risk 0.00cvss epss 0.07

    MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

  • CVE-2014-3145May 11, 2014
    risk 0.00cvss epss 0.01

    The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via…

  • CVE-2014-1522Apr 30, 2014
    risk 0.00cvss epss 0.05

    The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and…