Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-09-03 CVE-2018-16403 Out-of-bounds Read vulnerability in Elfutils Project Elfutils 0.173
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.
local
low complexity
elfutils-project CWE-125
5.5
2018-09-03 CVE-2018-16382 Out-of-bounds Read vulnerability in Nasm Netwide Assembler 2.14
Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.
local
low complexity
nasm CWE-125
5.5
2018-09-03 CVE-2018-16368 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
local
low complexity
xpdfreader CWE-125
5.5
2018-09-02 CVE-2018-16336 Out-of-bounds Read vulnerability in multiple products
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
network
low complexity
exiv2 debian canonical CWE-125
6.5
2018-09-01 CVE-2018-15161 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15160 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15159 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15158 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15157 Out-of-bounds Read vulnerability in Libfsclfs Project Libfsclfs 20170206
The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer over-read via a crafted clfs file.
network
low complexity
libfsclfs-project CWE-125
6.5
2018-08-30 CVE-2018-15363 Out-of-bounds Read vulnerability in Trendmicro products
An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations.
local
low complexity
trendmicro CWE-125
7.8