VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,337)

page 459 of 467
  • CVE-2019-15925HigSep 4, 2019
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.

  • CVE-2019-15918HigSep 4, 2019
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.

  • CVE-2019-15026HigAug 30, 2019
    risk 0.00cvss 7.5epss 0.03

    memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.

  • CVE-2019-15666MedAug 27, 2019
    risk 0.00cvss 4.4epss 0.02

    An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.

  • CVE-2019-15550HigAug 26, 2019
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect crossing of a page boundary.

  • CVE-2019-15147MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.01

    GoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c.

  • CVE-2019-15146MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.01

    GoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c.

  • CVE-2019-15141MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.02

    WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec,…

  • CVE-2019-15139MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.04

    The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a…

  • CVE-2019-15090MedAug 16, 2019
    risk 0.00cvss 6.7epss 0.00

    An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.

  • CVE-2019-13222HigAug 15, 2019
    risk 0.00cvss 7.1epss 0.01

    An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.

  • CVE-2019-14463CriJul 31, 2019
    risk 0.00cvss 9.1epss 0.02

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.

  • CVE-2019-14462CriJul 31, 2019
    risk 0.00cvss 9.1epss 0.02

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

  • CVE-2019-14283MedJul 26, 2019
    risk 0.00cvss 6.8epss 0.01

    In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged local user when a floppy disk has been inserted. NOTE: QEMU…

  • CVE-2018-20854HigJul 26, 2019
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl->phys out-of-bounds read.

  • CVE-2019-13615MedJul 16, 2019
    risk 0.00cvss 5.5epss 0.03

    libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.

  • CVE-2019-13504MedJul 11, 2019
    risk 0.00cvss 6.5epss 0.02

    There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

  • CVE-2019-13503HigJul 11, 2019
    risk 0.00cvss 7.5epss 0.01

    mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

  • CVE-2019-13391HigJul 7, 2019
    risk 0.00cvss 8.8epss 0.03

    In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.

  • CVE-2019-13303HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.