VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 173 of 472
  • CVE-2017-6800HigMar 10, 2017
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.

  • CVE-2017-2786HigMar 10, 2017
    risk 0.49cvss 7.5epss 0.02

    A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to an out of bounds read causing a crash and a denial of service.

  • CVE-2016-7969HigMar 3, 2017
    risk 0.49cvss 7.5epss 0.04

    The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."

  • CVE-2017-5356HigMar 3, 2017
    risk 0.49cvss 7.5epss 0.04

    Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).

  • CVE-2017-5196HigMar 3, 2017
    risk 0.49cvss 7.5epss 0.05

    Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.

  • CVE-2017-5195HigMar 3, 2017
    risk 0.49cvss 7.5epss 0.05

    Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.

  • CVE-2016-5043HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.04

    The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.

  • CVE-2016-5040HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.04

    libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.

  • CVE-2016-5039HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.04

    The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.

  • CVE-2016-5038HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.04

    The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.

  • CVE-2016-5036HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.04

    The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.

  • CVE-2017-6004HigFeb 16, 2017
    risk 0.49cvss 7.5epss 0.04

    The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

  • CVE-2016-8689HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.

  • CVE-2016-8682HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.

  • CVE-2017-2981HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2980HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2979HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2978HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2977HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2976HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.