VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,841)

page 32 of 93
  • CVE-2016-5039HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.

  • CVE-2016-5038HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.

  • CVE-2016-5036HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.

  • CVE-2017-6004HigFeb 16, 2017
    risk 0.49cvss 7.5epss 0.03

    The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

  • CVE-2016-8689HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.01

    The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.

  • CVE-2016-8682HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.02

    The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.

  • CVE-2017-2981HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2980HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2979HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2978HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2977HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2976HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2975HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-2974HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.03

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-5848HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.

  • CVE-2017-5847HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.

  • CVE-2017-5845HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.02

    The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.

  • CVE-2017-5841HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.02

    The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.

  • CVE-2017-5840HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.

  • CVE-2017-5838HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.02

    The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.