CWE-125— Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
9,162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-125page 10 of 184
- CVE-2017-12900CRITICALCVSS 9.8EG 9.82017-09-14
Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in util-print.c:tok2strbuf().
- CVE-2017-12901CRITICALCVSS 9.8EG 9.82017-09-14
The EIGRP parser in tcpdump before 4.9.2 has a buffer over-read in print-eigrp.c:eigrp_print().
- CVE-2017-12902CRITICALCVSS 9.8EG 9.82017-09-14
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
- CVE-2017-12933CRITICALCVSS 9.8EG 9.82017-08-18
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an…
- CVE-2017-12935HIGHCVSS 8.8EG 8.82017-08-18
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
- CVE-2017-12937HIGHCVSS 8.8EG 8.82017-08-18
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
- CVE-2017-12940CRITICALCVSS 9.8EG 9.82017-08-18
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
- CVE-2017-12941CRITICALCVSS 9.8EG 9.82017-08-18
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
- CVE-2017-12951MEDIUMCVSS 6.5EG 6.52017-08-28
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.
- CVE-2017-12954MEDIUMCVSS 6.5EG 6.52017-08-28
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.
- CVE-2017-12956MEDIUMCVSS 6.5EG 6.52017-08-18
There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.
- CVE-2017-12957MEDIUMCVSS 6.5EG 6.52017-08-18
There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to remote denial of service.
- CVE-2017-12958HIGHCVSS 7.5EG 7.52017-08-18
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
- CVE-2017-12963HIGHCVSS 7.5EG 7.52017-08-18
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix …
- CVE-2017-12967MEDIUMCVSS 6.5EG 6.52017-08-19
The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a …
- CVE-2017-12985CRITICALCVSS 9.8EG 9.82017-09-14
The IPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-ip6.c:ip6_print().
- CVE-2017-12986CRITICALCVSS 9.8EG 9.82017-09-14
The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
- CVE-2017-12987CRITICALCVSS 9.8EG 9.82017-09-14
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
- CVE-2017-12988CRITICALCVSS 9.8EG 9.82017-09-14
The telnet parser in tcpdump before 4.9.2 has a buffer over-read in print-telnet.c:telnet_parse().
- CVE-2017-12990CRITICALCVSS 9.8EG 9.82017-09-14
The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.
- CVE-2017-12991CRITICALCVSS 9.8EG 9.82017-09-14
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().
- CVE-2017-12992CRITICALCVSS 9.8EG 9.82017-09-14
The RIPng parser in tcpdump before 4.9.2 has a buffer over-read in print-ripng.c:ripng_print().
- CVE-2017-12993CRITICALCVSS 9.8EG 9.82017-09-14
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c, several functions.
- CVE-2017-12994CRITICALCVSS 9.8EG 9.82017-09-14
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().
- CVE-2017-12995CRITICALCVSS 9.8EG 9.82017-09-14
The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
- CVE-2017-12996CRITICALCVSS 9.8EG 9.82017-09-14
The PIMv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c:pimv2_print().
- CVE-2017-12997CRITICALCVSS 9.8EG 9.82017-09-14
The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().
- CVE-2017-12998CRITICALCVSS 9.8EG 9.82017-09-14
The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_extd_ip_reach().
- CVE-2017-12999CRITICALCVSS 9.8EG 9.82017-09-14
The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print().
- CVE-2017-13000CRITICALCVSS 9.8EG 9.82017-09-14
The IEEE 802.15.4 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_15_4.c:ieee802_15_4_if_print().
- CVE-2017-13001CRITICALCVSS 9.8EG 9.82017-09-14
The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:nfs_printfh().
- CVE-2017-13002CRITICALCVSS 9.8EG 9.82017-09-14
The AODV parser in tcpdump before 4.9.2 has a buffer over-read in print-aodv.c:aodv_extension().
- CVE-2017-13003CRITICALCVSS 9.8EG 9.82017-09-14
The LMP parser in tcpdump before 4.9.2 has a buffer over-read in print-lmp.c:lmp_print().
- CVE-2017-13004CRITICALCVSS 9.8EG 9.82017-09-14
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().
- CVE-2017-13005CRITICALCVSS 9.8EG 9.82017-09-14
The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:xid_map_enter().
- CVE-2017-13006CRITICALCVSS 9.8EG 9.82017-09-14
The L2TP parser in tcpdump before 4.9.2 has a buffer over-read in print-l2tp.c, several functions.
- CVE-2017-13007CRITICALCVSS 9.8EG 9.82017-09-14
The Apple PKTAP parser in tcpdump before 4.9.2 has a buffer over-read in print-pktap.c:pktap_if_print().
- CVE-2017-13008CRITICALCVSS 9.8EG 9.82017-09-14
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
- CVE-2017-13009CRITICALCVSS 9.8EG 9.82017-09-14
The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print().
- CVE-2017-13010CRITICALCVSS 9.8EG 9.82017-09-14
The BEEP parser in tcpdump before 4.9.2 has a buffer over-read in print-beep.c:l_strnstart().
- CVE-2017-13012CRITICALCVSS 9.8EG 9.82017-09-14
The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
- CVE-2017-13013CRITICALCVSS 9.8EG 9.82017-09-14
The ARP parser in tcpdump before 4.9.2 has a buffer over-read in print-arp.c, several functions.
- CVE-2017-13014CRITICALCVSS 9.8EG 9.82017-09-14
The White Board protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-wb.c:wb_prep(), several functions.
- CVE-2017-13015CRITICALCVSS 9.8EG 9.82017-09-14
The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap_print().
- CVE-2017-13016CRITICALCVSS 9.8EG 9.82017-09-14
The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print().
- CVE-2017-13017CRITICALCVSS 9.8EG 9.82017-09-14
The DHCPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-dhcp6.c:dhcp6opt_print().
- CVE-2017-13018CRITICALCVSS 9.8EG 9.82017-09-14
The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().
- CVE-2017-13019CRITICALCVSS 9.8EG 9.82017-09-14
The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().
- CVE-2017-13020CRITICALCVSS 9.8EG 9.82017-09-14
The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().
- CVE-2017-13021CRITICALCVSS 9.8EG 9.82017-09-14
The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_print().
Map vulnerabilities like CWE-125 to your infrastructure
EchelonGraph correlates every CVE — across CWE-125 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →