VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (1,460)

page 56 of 73
  • CVE-2017-9472MedJun 7, 2017
    risk 0.36cvss 5.5epss 0.00

    In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • CVE-2017-9471MedJun 7, 2017
    risk 0.36cvss 5.5epss 0.00

    In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • CVE-2017-8313MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

  • CVE-2017-8312MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.

  • CVE-2017-8310MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

  • CVE-2017-9044MedMay 18, 2017
    risk 0.36cvss 5.5epss 0.00

    The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.

  • CVE-2017-9041MedMay 18, 2017
    risk 0.36cvss 5.5epss 0.00

    GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c.

  • CVE-2017-9038MedMay 18, 2017
    risk 0.36cvss 5.5epss 0.00

    GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets.

  • CVE-2017-8908MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

  • CVE-2017-8845MedMay 8, 2017
    risk 0.36cvss 5.5epss 0.00

    The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

  • CVE-2017-8374MedMay 1, 2017
    risk 0.36cvss 5.5epss 0.00

    The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

  • CVE-2017-7718MedApr 20, 2017
    risk 0.36cvss 5.5epss 0.00

    hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.

  • CVE-2017-7960MedApr 19, 2017
    risk 0.36cvss 5.5epss 0.00

    The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

  • CVE-2017-7939MedApr 18, 2017
    risk 0.36cvss 5.5epss 0.00

    The read_next_pam_token function in imagew-pnm.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted file.

  • CVE-2017-7854MedApr 13, 2017
    risk 0.36cvss 5.5epss 0.00

    The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

  • CVE-2017-7716MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.00

    The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

  • CVE-2017-3053MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of the APP13 segment in JPEG files.

  • CVE-2017-3052MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of EMF - enhanced meta file format.

  • CVE-2017-3046MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to contiguous code-stream parsing.

  • CVE-2017-3045MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.