VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 250 of 472
  • CVE-2019-6286MedJan 14, 2019
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.

  • CVE-2019-6284MedJan 14, 2019
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.

  • CVE-2019-6283MedJan 14, 2019
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.

  • CVE-2018-6143MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-16082MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2019-3572MedJan 2, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call to png_write_row in libpng, an out-of-bounds write might…

  • CVE-2018-20591MedDec 30, 2018
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by swftocxx.

  • CVE-2018-20588MedDec 30, 2018
    risk 0.42cvss 6.5epss 0.01

    lib/support/unicodeconv/unicodeconv.c in libotfcc.a in otfcc v0.10.3-alpha has a buffer over-read.

  • CVE-2018-20570MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.02

    jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

  • CVE-2018-20536MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

  • CVE-2018-20453MedDec 25, 2018
    risk 0.42cvss 6.5epss 0.01

    The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2018-20451MedDec 25, 2018
    risk 0.42cvss 6.5epss 0.01

    The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2018-20430MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.

  • CVE-2018-20409MedDec 23, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by mp42hls.

  • CVE-2018-20098MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.03

    There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-20096MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.03

    There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-19758MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

  • CVE-2018-19664MedNov 29, 2018
    risk 0.42cvss 6.5epss 0.02

    libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

  • CVE-2018-19661MedNov 29, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.

  • CVE-2018-5916MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.00

    Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD…