VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,761)

page 32 of 489
  • CVE-2017-16376HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is…

  • CVE-2017-16374HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the JPEG 2000 module. An…

  • CVE-2017-16370HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs because of a computation that reads data that is past…

  • CVE-2017-16365HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the True Type2 Font parsing…

  • CVE-2017-16363HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the module that handles…

  • CVE-2017-16362HigDec 9, 2017
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of an out of bounds read vulnerability in the…

  • CVE-2017-8817CriNov 29, 2017
    risk 0.58cvss 9.8epss 0.11

    The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.

  • CVE-2017-9935HigJun 26, 2017
    risk 0.58cvss 8.8epss 0.04

    In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invalid free in TIFFClose or…

  • CVE-2017-8454HigMay 3, 2017
    risk 0.58cvss 8.8epss 0.04

    Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.

  • CVE-2017-8453HigMay 3, 2017
    risk 0.58cvss 8.8epss 0.04

    Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.

  • CVE-2016-6491HigDec 13, 2016
    risk 0.58cvss 8.8epss 0.06

    Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.

  • CVE-1999-0029HigJul 16, 1997
    risk 0.58cvss 8.4epss 0.01

    root privileges via buffer overflow in ordist command on SGI IRIX systems.

  • CVE-2026-55211CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking…

  • CVE-2026-55209CriSep 14, 2026
    risk 0.57cvss 9.8epss 0.00

    resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp…

  • CVE-2026-87440HigSep 9, 2026
    risk 0.57cvss 8.8epss 0.00

    Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-80096HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-78518HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69494HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69334HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62706HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.