VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,841)

page 33 of 93
  • CVE-2016-10199HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.02

    The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.

  • CVE-2016-7449HigFeb 6, 2017
    risk 0.49cvss 7.5epss 0.04

    The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.

  • CVE-2017-5601HigJan 27, 2017
    risk 0.49cvss 7.5epss 0.01

    An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.

  • CVE-2016-5827HigJan 27, 2017
    risk 0.49cvss 7.5epss 0.01

    The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

  • CVE-2016-5826HigJan 27, 2017
    risk 0.49cvss 7.5epss 0.01

    The parser_get_next_char function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) by crafting a string to the icalparser_parse_string function.

  • CVE-2016-9297HigJan 18, 2017
    risk 0.49cvss 7.5epss 0.00

    The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.

  • CVE-2016-9109HigJan 18, 2017
    risk 0.49cvss 7.5epss 0.01

    Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.

  • CVE-2016-7563HigJan 18, 2017
    risk 0.49cvss 7.5epss 0.00

    The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.

  • CVE-2016-9812HigJan 13, 2017
    risk 0.49cvss 7.5epss 0.02

    The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.

  • CVE-2016-6891HigJan 5, 2017
    risk 0.49cvss 7.5epss 0.03

    MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate.

  • CVE-2016-9037HigDec 23, 2016
    risk 0.49cvss 7.5epss 0.03

    An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the…

  • CVE-2016-9036HigDec 23, 2016
    risk 0.49cvss 7.5epss 0.01

    An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside…

  • CVE-2016-7945HigDec 13, 2016
    risk 0.49cvss 7.5epss 0.01

    Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.

  • CVE-2016-5842HigDec 13, 2016
    risk 0.49cvss 7.5epss 0.01

    MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

  • CVE-2016-9918HigDec 8, 2016
    risk 0.49cvss 7.5epss 0.00

    In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

  • CVE-2016-8876HigOct 31, 2016
    risk 0.49cvss 7.5epss 0.00

    Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at…

  • CVE-2016-7506HigOct 29, 2016
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploitation of this issue can lead to code execution or denial of service condition.

  • CVE-2016-9017HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.00

    Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction…

  • CVE-2016-3658HigOct 3, 2016
    risk 0.49cvss 7.5epss 0.01

    The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.

  • CVE-2016-3634HigOct 3, 2016
    risk 0.49cvss 7.5epss 0.01

    The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.