VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,460)

page 44 of 73
  • CVE-2017-13134MedAug 23, 2017
    risk 0.42cvss 6.5epss 0.01

    In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-12967MedAug 19, 2017
    risk 0.42cvss 6.5epss 0.01

    The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.

  • CVE-2017-12957MedAug 18, 2017
    risk 0.42cvss 6.5epss 0.01

    There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to remote denial of service.

  • CVE-2017-12956MedAug 18, 2017
    risk 0.42cvss 6.5epss 0.01

    There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.

  • CVE-2017-12445MedAug 17, 2017
    risk 0.42cvss 6.5epss 0.00

    The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

  • CVE-2017-12444MedAug 17, 2017
    risk 0.42cvss 6.5epss 0.00

    The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

  • CVE-2017-12443MedAug 17, 2017
    risk 0.42cvss 6.5epss 0.00

    The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

  • CVE-2017-12442MedAug 17, 2017
    risk 0.42cvss 6.5epss 0.00

    The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

  • CVE-2017-12441MedAug 17, 2017
    risk 0.42cvss 6.5epss 0.00

    The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

  • CVE-2017-11753MedJul 30, 2017
    risk 0.42cvss 6.5epss 0.01

    The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.

  • CVE-2017-11722MedJul 28, 2017
    risk 0.42cvss 6.5epss 0.01

    The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.

  • CVE-2017-11704MedJul 28, 2017
    risk 0.42cvss 6.5epss 0.00

    A heap-based buffer over-read was found in the function decompileIF in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-11639MedJul 26, 2017
    risk 0.42cvss 6.5epss 0.00

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h.

  • CVE-2017-11608MedJul 24, 2017
    risk 0.42cvss 6.5epss 0.01

    There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-11605MedJul 24, 2017
    risk 0.42cvss 6.5epss 0.01

    There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-11540MedJul 23, 2017
    risk 0.42cvss 6.5epss 0.00

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called from the WritePICONImage function in coders/xpm.c.

  • CVE-2017-11535MedJul 23, 2017
    risk 0.42cvss 6.5epss 0.00

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WritePSImage() function in coders/ps.c.

  • CVE-2017-11533MedJul 23, 2017
    risk 0.42cvss 6.5epss 0.00

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uil.c.

  • CVE-2017-11336MedJul 17, 2017
    risk 0.42cvss 6.5epss 0.01

    There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

  • CVE-2014-8127MedJun 26, 2017
    risk 0.42cvss 6.5epss 0.01

    LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.