CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 171 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-12963 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2017 | There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24). | ||
| CVE-2017-12958 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2017 | There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. | ||
| CVE-2017-9454 | Hig | 0.49 | 7.5 | 0.02 | Aug 18, 2017 | Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response. | ||
| CVE-2017-12067 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2017 | Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c. | ||
| CVE-2017-11670 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2017 | A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted… | ||
| CVE-2017-11669 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2017 | An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by… | ||
| CVE-2017-11668 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2017 | An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by… | ||
| CVE-2017-10987 | Hig | 0.49 | 7.5 | 0.03 | Jul 17, 2017 | An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service. | ||
| CVE-2017-10982 | Hig | 0.49 | 7.5 | 0.03 | Jul 17, 2017 | An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service. | ||
| CVE-2017-11367 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data. | ||
| CVE-2017-9814 | Hig | 0.49 | 7.5 | 0.03 | Jul 17, 2017 | cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. | ||
| CVE-2017-11341 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2017-11108 | Hig | 0.49 | 7.5 | 0.05 | Jul 8, 2017 | tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol. | ||
| CVE-2017-10976 | Hig | 0.49 | 7.5 | 0.01 | Jul 6, 2017 | When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c. | ||
| CVE-2017-10687 | Hig | 0.49 | 7.5 | 0.02 | Jun 29, 2017 | In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2017-10683 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 29, 2017 | In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack. | |
| CVE-2017-9359 | Hig | 0.49 | 7.5 | 0.04 | Jun 2, 2017 | The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a… | ||
| CVE-2017-9189 | Hig | 0.49 | 7.5 | 0.02 | May 23, 2017 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLOR function in color.c:16:11. | ||
| CVE-2017-9180 | Hig | 0.49 | 7.5 | 0.02 | May 23, 2017 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:440:14. | ||
| CVE-2017-9179 | Hig | 0.49 | 7.5 | 0.02 | May 23, 2017 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14. |
- risk 0.49cvss 7.5epss 0.01
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).
- risk 0.49cvss 7.5epss 0.01
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
- risk 0.49cvss 7.5epss 0.02
Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response.
- risk 0.49cvss 7.5epss 0.01
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
- risk 0.49cvss 7.5epss 0.01
A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted…
- risk 0.49cvss 7.5epss 0.01
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by…
- risk 0.49cvss 7.5epss 0.01
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by…
- risk 0.49cvss 7.5epss 0.03
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
- risk 0.49cvss 7.5epss 0.03
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
- risk 0.49cvss 7.5epss 0.01
The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.
- risk 0.49cvss 7.5epss 0.03
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
- risk 0.49cvss 7.5epss 0.02
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
- risk 0.49cvss 7.5epss 0.05
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
- risk 0.49cvss 7.5epss 0.01
When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.
- risk 0.49cvss 7.5epss 0.02
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.
- risk 0.49cvss 7.5epss 0.01
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
- risk 0.49cvss 7.5epss 0.04
The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a…
- risk 0.49cvss 7.5epss 0.02
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLOR function in color.c:16:11.
- risk 0.49cvss 7.5epss 0.02
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:440:14.
- risk 0.49cvss 7.5epss 0.02
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14.