VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,841)

page 30 of 93
  • CVE-2017-11367HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.

  • CVE-2017-9814HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.00

    cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.

  • CVE-2017-11341HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.01

    There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-11108HigJul 8, 2017
    risk 0.49cvss 7.5epss 0.01

    tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.

  • CVE-2017-10976HigJul 6, 2017
    risk 0.49cvss 7.5epss 0.00

    When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.

  • CVE-2017-10687HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.01

    In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-10683HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.01

    In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-9359HigJun 2, 2017
    risk 0.49cvss 7.5epss 0.00

    The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a…

  • CVE-2017-9189HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLOR function in color.c:16:11.

  • CVE-2017-9180HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:440:14.

  • CVE-2017-9179HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14.

  • CVE-2017-9177HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:390:12.

  • CVE-2017-9174HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:21:23.

  • CVE-2017-9155HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the input_pnm_reader function in input-pnm.c:243:3.

  • CVE-2017-9154HigMay 23, 2017
    risk 0.49cvss 7.5epss 0.01

    libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:16:11.

  • CVE-2017-9050HigMay 18, 2017
    risk 0.49cvss 7.5epss 0.00

    libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.

  • CVE-2017-9049HigMay 18, 2017
    risk 0.49cvss 7.5epss 0.00

    libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug…

  • CVE-2017-6658HigMay 16, 2017
    risk 0.49cvss 7.5epss 0.00

    Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing the array size solves this problem.

  • CVE-2017-7483HigMay 2, 2017
    risk 0.49cvss 7.5epss 0.01

    Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.

  • CVE-2017-8393HigMay 1, 2017
    risk 0.49cvss 7.5epss 0.00

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always named starting with a…