Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-09-10 CVE-2018-16790 Out-of-bounds Read vulnerability in Mongodb Libbson 1.12.0
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
network
low complexity
mongodb CWE-125
8.1
2018-09-10 CVE-2018-16764 Out-of-bounds Read vulnerability in Webassembly Virtual Machine Project Webassembly Virtual Machine
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catch_all heap-based buffer over-read.
8.8
2018-09-07 CVE-2018-16667 Out-of-bounds Read vulnerability in Contiki-Ng Contiki-Ng.
An issue was discovered in Contiki-NG through 4.1.
local
high complexity
contiki-ng CWE-125
7.0
2018-09-06 CVE-2018-1000668 Out-of-bounds Read vulnerability in Jsish 2.4.702.047
jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can result in Crash due to segmentation fault.
network
low complexity
jsish CWE-125
6.5
2018-09-04 CVE-2018-16438 Out-of-bounds Read vulnerability in Hdfgroup Hdf5 1.8.20
An issue was discovered in the HDF HDF5 1.8.20 library.
network
low complexity
hdfgroup CWE-125
8.8
2018-09-04 CVE-2018-16430 Out-of-bounds Read vulnerability in multiple products
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
network
low complexity
gnu debian CWE-125
8.8
2018-09-04 CVE-2018-16429 Out-of-bounds Read vulnerability in multiple products
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
network
low complexity
gnome canonical CWE-125
7.5
2018-09-04 CVE-2018-16427 Out-of-bounds Read vulnerability in Opensc Project Opensc
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
low complexity
opensc-project CWE-125
4.3
2018-09-03 CVE-2018-16413 Out-of-bounds Read vulnerability in Imagemagick 7.0.811
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.
network
low complexity
imagemagick CWE-125
8.8
2018-09-03 CVE-2018-16412 Out-of-bounds Read vulnerability in multiple products
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
network
low complexity
imagemagick opensuse CWE-125
8.8