CWE-125— Out-of-bounds Read
7,779 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-125page 52 of 156
- CVE-2020-5965MEDIUMCVSS 5.5EG 5.52020-06-25
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.
- CVE-2020-5971HIGHCVSS 7.8EG 7.82020-06-30
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, whic…
- CVE-2020-5991HIGHCVSS 7.8EG 7.82020-10-30
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
- CVE-2020-6058CRITICALCVSS 9.1EG 9.12020-02-04
An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitiv…
- CVE-2020-6059HIGHCVSS 8.2EG 8.22020-02-04
An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information discl…
- CVE-2020-6061CRITICALCVSS 9.8EG 9.82020-02-19
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an …
- CVE-2020-6077HIGHCVSS 7.5EG 7.52020-03-24
An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, po…
- CVE-2020-6104MEDIUMCVSS 5.5EG 5.52020-10-15
An exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause information disclosure resulting in a information disclosure. An …
- CVE-2020-6106MEDIUMCVSS 5.5EG 5.52020-10-15
An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a maliciou…
- CVE-2020-6107MEDIUMCVSS 5.5EG 5.52020-10-15
An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker …
- CVE-2020-6162CRITICALCVSS 9.1EG 9.12020-01-10
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
- CVE-2020-6322MEDIUMCVSS 4.3EG 4.32020-09-09
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the applicat…
- CVE-2020-6330MEDIUMCVSS 4.3EG 4.32020-09-09
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the applicat…
- CVE-2020-6341MEDIUMCVSS 4.3EG 4.32020-09-09
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated EPS file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the applicat…
- CVE-2020-6345MEDIUMCVSS 4.3EG 4.32020-09-09
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the applicat…
- CVE-2020-6374HIGHCVSS 7.8EG 7.82020-10-15
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user…
- CVE-2020-6395MEDIUMCVSS 6.5EG 6.52020-02-11
Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-6405MEDIUMCVSS 6.5EG 6.52020-02-11
Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-6447HIGHCVSS 8.8EG 8.82020-04-13
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6455HIGHCVSS 8.8EG 8.82020-04-13
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6458HIGHCVSS 8.8EG 8.82020-05-21
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- CVE-2020-6555HIGHCVSS 7.6EG 7.62020-09-21
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-6609HIGHCVSS 8.8EG 8.82020-01-08
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
- CVE-2020-6612HIGHCVSS 8.1EG 8.12020-01-08
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
- CVE-2020-6613HIGHCVSS 8.1EG 8.12020-01-08
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
- CVE-2020-6614HIGHCVSS 8.1EG 8.12020-01-08
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
- CVE-2020-6618HIGHCVSS 8.8EG 8.82020-01-08
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
- CVE-2020-6620HIGHCVSS 8.8EG 8.82020-01-08
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
- CVE-2020-6621HIGHCVSS 8.8EG 8.82020-01-08
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
- CVE-2020-6622HIGHCVSS 8.8EG 8.82020-01-08
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
- CVE-2020-6624HIGHCVSS 7.1EG 7.12020-01-09
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
- CVE-2020-6625HIGHCVSS 7.1EG 7.12020-01-09
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
- CVE-2020-6628HIGHCVSS 8.8EG 8.82020-01-09
Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.
- CVE-2020-6655MEDIUMCVSS 5.8EG 5.82021-01-07
The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed…
- CVE-2020-6793MEDIUMCVSS 6.5EG 6.52020-03-02
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.
- CVE-2020-6806HIGHCVSS 8.8EG 8.82020-03-25
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerabi…
- CVE-2020-6976MEDIUMCVSS 5.5EG 5.52020-03-18
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.
- CVE-2020-7044HIGHCVSS 7.5EG 7.52020-01-16
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
- CVE-2020-7059MEDIUMCVSS 6.5EG 9.12020-02-10
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This…
- CVE-2020-7060MEDIUMCVSS 6.5EG 9.12020-02-10
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read pas…
- CVE-2020-7061MEDIUMCVSS 6.5EG 9.12020-02-27
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to i…
- CVE-2020-7064MEDIUMCVSS 6.5EG 5.42020-04-01
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potent…
- CVE-2020-7067HIGHCVSS 7.5EG 7.52020-04-27
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signe…
- CVE-2020-7466HIGHCVSS 7.5EG 7.52020-10-06
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.
- CVE-2020-7557HIGHCVSS 7.8EG 7.82020-11-19
A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
- CVE-2020-7562HIGHCVSS 8.1EG 8.12020-11-18
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault o…
- CVE-2020-7816HIGHCVSS 7.0EG 7.02020-06-30
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on an affected device.nThe vulnerability is due to a stack over…
- CVE-2020-7853MEDIUMCVSS 5.5EG 5.52021-03-24
An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker can exploit arbitrary code execution.
- CVE-2020-8036HIGHCVSS 7.5EG 7.52020-11-04
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
- CVE-2020-8244MEDIUMCVSS 6.5EG 6.52020-08-30
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be …
Map vulnerabilities like CWE-125 to your infrastructure
EchelonGraph correlates every CVE — across CWE-125 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →