CWE-125— Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
9,162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-125page 9 of 184
- CVE-2017-11661HIGHCVSS 7.5EG 7.52017-08-17
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
- CVE-2017-11662HIGHCVSS 7.5EG 7.52017-08-17
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
- CVE-2017-11663MEDIUMCVSS 6.5EG 6.52017-08-17
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
- CVE-2017-11664MEDIUMCVSS 6.5EG 6.52017-08-17
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
- CVE-2017-11668HIGHCVSS 7.5EG 7.52017-07-31
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass proce…
- CVE-2017-11669HIGHCVSS 7.5EG 7.52017-07-31
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass proce…
- CVE-2017-11670HIGHCVSS 7.5EG 7.52017-07-31
A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass p…
- CVE-2017-11704MEDIUMCVSS 6.5EG 6.52017-07-28
A heap-based buffer over-read was found in the function decompileIF in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11714HIGHCVSS 7.8EG 7.82017-07-28
psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScrip…
- CVE-2017-11719HIGHCVSS 7.8EG 7.82017-07-28
The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a crafted DNxHD file.
- CVE-2017-11722MEDIUMCVSS 6.5EG 6.52017-07-28
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was incons…
- CVE-2017-11728MEDIUMCVSS 5.5EG 5.52017-07-29
A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11729MEDIUMCVSS 5.5EG 5.52017-07-29
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11730MEDIUMCVSS 5.5EG 5.52017-07-29
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11731MEDIUMCVSS 5.5EG 5.52017-07-29
An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11734MEDIUMCVSS 5.5EG 5.52017-07-29
A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-11753MEDIUMCVSS 6.5EG 6.52017-07-30
The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.
- CVE-2017-12067HIGHCVSS 7.5EG 7.52017-08-01
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
- CVE-2017-12142MEDIUMCVSS 5.5EG 5.52017-08-02
In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-12369CRITICALCVSS 9.6EG 9.62017-11-30
A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providi…
- CVE-2017-12377CRITICALCVSS 9.8EG 9.82018-01-26
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The …
- CVE-2017-12378MEDIUMCVSS 5.5EG 5.52018-01-26
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input…
- CVE-2017-12441MEDIUMCVSS 6.5EG 6.52017-08-17
The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
- CVE-2017-12442MEDIUMCVSS 6.5EG 6.52017-08-17
The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
- CVE-2017-12443MEDIUMCVSS 6.5EG 6.52017-08-17
The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
- CVE-2017-12444MEDIUMCVSS 6.5EG 6.52017-08-17
The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
- CVE-2017-12445MEDIUMCVSS 6.5EG 6.52017-08-17
The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
- CVE-2017-12449HIGHCVSS 7.8EG 7.82017-08-04
The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms …
- CVE-2017-12451HIGHCVSS 7.8EG 7.82017-08-04
The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds s…
- CVE-2017-12452HIGHCVSS 7.8EG 7.82017-08-04
The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read…
- CVE-2017-12453HIGHCVSS 7.8EG 7.82017-08-04
The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha fil…
- CVE-2017-12454HIGHCVSS 7.8EG 7.82017-08-04
The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alph…
- CVE-2017-12455HIGHCVSS 7.8EG 7.82017-08-04
The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha f…
- CVE-2017-12456HIGHCVSS 7.8EG 7.82017-08-04
The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file.
- CVE-2017-12458HIGHCVSS 7.8EG 7.82017-08-04
The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafte…
- CVE-2017-12596HIGHCVSS 7.8EG 7.82017-08-07
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
- CVE-2017-12598HIGHCVSS 8.8EG 8.82017-08-07
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the…
- CVE-2017-12599HIGHCVSS 8.8EG 8.82017-08-07
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
- CVE-2017-12613HIGHCVSS 7.1EG 7.12017-10-24
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, po…
- CVE-2017-12618MEDIUMCVSS 4.7EG 4.72017-10-24
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the databas…
- CVE-2017-12640HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.
- CVE-2017-12722MEDIUMCVSS 5.3EG 5.32018-02-15
An Out-of-bounds Read issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump reads memory out of bounds, causing the communications module t…
- CVE-2017-12839HIGHCVSS 8.3EG 8.32019-05-09
A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a cr…
- CVE-2017-12893CRITICALCVSS 9.8EG 9.82017-09-14
The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().
- CVE-2017-12894CRITICALCVSS 9.8EG 9.82017-09-14
Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().
- CVE-2017-12895CRITICALCVSS 9.8EG 9.82017-09-14
The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
- CVE-2017-12896CRITICALCVSS 9.8EG 9.82017-09-14
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
- CVE-2017-12897CRITICALCVSS 9.8EG 9.82017-09-14
The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().
- CVE-2017-12898CRITICALCVSS 9.8EG 9.82017-09-14
The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:interp_reply().
- CVE-2017-12899CRITICALCVSS 9.8EG 9.82017-09-14
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
Map vulnerabilities like CWE-125 to your infrastructure
EchelonGraph correlates every CVE — across CWE-125 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →