VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 171 of 472
  • CVE-2017-12963HigAug 18, 2017
    risk 0.49cvss 7.5epss 0.01

    There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).

  • CVE-2017-12958HigAug 18, 2017
    risk 0.49cvss 7.5epss 0.01

    There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

  • CVE-2017-9454HigAug 18, 2017
    risk 0.49cvss 7.5epss 0.02

    Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response.

  • CVE-2017-12067HigAug 1, 2017
    risk 0.49cvss 7.5epss 0.01

    Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.

  • CVE-2017-11670HigJul 31, 2017
    risk 0.49cvss 7.5epss 0.01

    A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted…

  • CVE-2017-11669HigJul 31, 2017
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by…

  • CVE-2017-11668HigJul 31, 2017
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by…

  • CVE-2017-10987HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.03

    An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.

  • CVE-2017-10982HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.03

    An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.

  • CVE-2017-11367HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.

  • CVE-2017-9814HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.03

    cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.

  • CVE-2017-11341HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.02

    There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-11108HigJul 8, 2017
    risk 0.49cvss 7.5epss 0.05

    tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.

  • CVE-2017-10976HigJul 6, 2017
    risk 0.49cvss 7.5epss 0.01

    When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.

  • CVE-2017-10687HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.02

    In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-10683HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.01

    In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-9359HigJun 2, 2017
    risk 0.49cvss 7.5epss 0.04

    The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a…

  • CVE-2017-9189HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.02

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLOR function in color.c:16:11.

  • CVE-2017-9180HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.02

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:440:14.

  • CVE-2017-9179HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.02

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14.