CWE-125— Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
9,162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-125page 7 of 184
- CVE-2016-9109HIGHCVSS 7.5EG 7.52017-01-18
Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.
- CVE-2016-9273MEDIUMCVSS 5.5EG 5.52017-01-18
tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
- CVE-2016-9276HIGHCVSS 7.5EG 7.52017-03-23
The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).
- CVE-2016-9297HIGHCVSS 7.5EG 7.52017-01-18
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.
- CVE-2016-9433MEDIUMCVSS 6.5EG 6.52016-12-12
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds array access) via a crafted HTML page.
- CVE-2016-9447HIGHCVSS 7.8EG 7.82017-01-23
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
- CVE-2016-9532MEDIUMCVSS 5.5EG 5.52017-02-06
Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
- CVE-2016-9539CRITICALCVSS 9.8EG 9.82016-11-22
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.
- CVE-2016-9555CRITICALCVSS 9.8EG 9.82016-11-28
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have …
- CVE-2016-9569MEDIUMCVSS 4.4EG 4.42018-02-12
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call.
- CVE-2016-9570HIGHCVSS 7.5EG 7.52018-02-12
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.
- CVE-2016-9573HIGHCVSS 6.5EG 8.12018-08-01
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the hea…
- CVE-2016-9583HIGHCVSS 5.5EG 7.82018-08-01
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
- CVE-2016-9598MEDIUMCVSS 6.5EG 6.52018-08-16
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML document. NOTE: this vulnerability exists because of a missing fi…
- CVE-2016-9642MEDIUMCVSS 5.5EG 5.52017-02-03
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
- CVE-2016-9773MEDIUMCVSS 5.5EG 5.52017-02-17
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. NOTE: this vulnerability…
- CVE-2016-9777HIGHCVSS 7.8EG 7.82016-12-28
KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) …
- CVE-2016-9797MEDIUMCVSS 5.3EG 5.32016-12-03
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
- CVE-2016-9803MEDIUMCVSS 5.3EG 5.32016-12-03
In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.
- CVE-2016-9807MEDIUMCVSS 5.5EG 5.52017-01-13
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
- CVE-2016-9809HIGHCVSS 7.8EG 7.82017-01-13
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.
- CVE-2016-9810MEDIUMCVSS 5.5EG 5.52017-01-13
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an in…
- CVE-2016-9811MEDIUMCVSS 4.7EG 4.72017-01-13
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
- CVE-2016-9812HIGHCVSS 7.5EG 7.52017-01-13
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.
- CVE-2016-9918HIGHCVSS 7.5EG 7.52016-12-08
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
- CVE-2016-9935CRITICALCVSS 9.8EG 9.82017-01-04
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via …
- CVE-2016-9953CRITICALCVSS 9.8EG 9.82018-03-12
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), …
- CVE-2016-9959HIGHCVSS 7.8EG 7.82017-04-12
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
- CVE-2017-0725MEDIUMCVSS 5.5EG 5.52017-08-09
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
- CVE-2017-0812HIGHCVSS 7.8EG 7.82017-10-04
An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62873231.
- CVE-2017-0854CRITICALCVSS 9.1EG 9.12017-11-16
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63873837.
- CVE-2017-1000126MEDIUMCVSS 5.5EG 5.52017-11-17
exiv2 0.26 contains a Stack out of bounds read in webp parser
- CVE-2017-1000128MEDIUMCVSS 5.5EG 5.52017-11-17
Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser
- CVE-2017-1000173CRITICALCVSS 9.8EG 9.82017-11-17
Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past…
- CVE-2017-10683HIGHCVSS 7.5EG 7.52017-06-29
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
- CVE-2017-10687HIGHCVSS 7.5EG 7.52017-06-29
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.
- CVE-2017-10928HIGHCVSS 8.8EG 8.82017-07-05
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document …
- CVE-2017-10942MEDIUMCVSS 6.5EG 6.52017-10-31
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
- CVE-2017-10943MEDIUMCVSS 6.5EG 6.52017-10-31
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
- CVE-2017-10944MEDIUMCVSS 6.5EG 6.52017-10-31
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
- CVE-2017-10956MEDIUMCVSS 6.5EG 6.52017-12-20
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
- CVE-2017-10976HIGHCVSS 7.5EG 7.52017-07-06
When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.
- CVE-2017-10982HIGHCVSS 7.5EG 7.52017-07-17
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
- CVE-2017-10987HIGHCVSS 7.5EG 7.52017-07-17
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
- CVE-2017-10989CRITICALCVSS 9.8EG 9.82017-07-07
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other imp…
- CVE-2017-10995MEDIUMCVSS 5.5EG 5.52017-07-07
The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.
- CVE-2017-11002MEDIUMCVSS 5.5EG 5.52017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
- CVE-2017-11035HIGHCVSS 7.8EG 7.82017-11-16
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, possible buffer overflow or information leak in the functions "sme_set_ft_ies" and "csr_roam_issue_ft_preauth_req" due to incor…
- CVE-2017-11052HIGHCVSS 7.5EG 7.52017-10-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_NDP cfg80211 vendor command a buffer over-read can occur.
- CVE-2017-11054HIGHCVSS 7.5EG 7.52017-10-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.
Map vulnerabilities like CWE-125 to your infrastructure
EchelonGraph correlates every CVE — across CWE-125 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →