VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,460)

page 53 of 73
  • CVE-2018-19759MedNov 30, 2018
    risk 0.36cvss 5.5epss 0.00

    There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.

  • CVE-2018-19756MedNov 30, 2018
    risk 0.36cvss 5.5epss 0.00

    There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.

  • CVE-2017-17812MedDec 21, 2017
    risk 0.36cvss 5.5epss 0.00

    In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.

  • CVE-2017-17788MedDec 20, 2017
    risk 0.36cvss 5.5epss 0.01

    In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

  • CVE-2017-17669MedDec 13, 2017
    risk 0.36cvss 5.5epss 0.00

    There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.

  • CVE-2017-17080MedNov 30, 2017
    risk 0.36cvss 5.5epss 0.00

    elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.

  • CVE-2017-1000128MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser

  • CVE-2017-1000126MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    exiv2 0.26 contains a Stack out of bounds read in webp parser

  • CVE-2017-16808MedNov 13, 2017
    risk 0.36cvss 5.5epss 0.02

    tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.

  • CVE-2017-16805MedNov 13, 2017
    risk 0.36cvss 5.5epss 0.00

    In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.

  • CVE-2017-13817MedNov 13, 2017
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions.

  • CVE-2017-16794MedNov 12, 2017
    risk 0.36cvss 5.5epss 0.00

    The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an erroneous png_load call that occurs because of incorrect integer data types in png2swf.

  • CVE-2017-15922MedOct 26, 2017
    risk 0.36cvss 5.5epss 0.00

    In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

  • CVE-2017-15045MedOct 6, 2017
    risk 0.36cvss 5.5epss 0.00

    LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.

  • CVE-2017-15021MedOct 5, 2017
    risk 0.36cvss 5.5epss 0.00

    bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.

  • CVE-2017-15018MedOct 5, 2017
    risk 0.36cvss 5.5epss 0.00

    LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.

  • CVE-2017-14931MedSep 30, 2017
    risk 0.36cvss 5.5epss 0.00

    ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted JPEG file.

  • CVE-2017-14860MedSep 29, 2017
    risk 0.36cvss 5.5epss 0.00

    There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

  • CVE-2017-11002MedSep 21, 2017
    risk 0.36cvss 5.5epss 0.00

    In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.

  • CVE-2017-14529MedSep 18, 2017
    risk 0.36cvss 5.5epss 0.00

    The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.