Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-05-31 CVE-2018-11598 Out-of-bounds Read vulnerability in Espruino
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.
local
low complexity
espruino CWE-125
7.1
2018-05-31 CVE-2018-11592 Out-of-bounds Read vulnerability in Espruino
Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via an Out-of-bounds Read during syntax parsing in which certain height validation is missing in libs/graphics/jswrap_graphics.c.
local
low complexity
espruino CWE-125
5.5
2018-05-31 CVE-2018-11576 Out-of-bounds Read vulnerability in Miniupnp Project Ngiflib 0.4
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
network
low complexity
miniupnp-project CWE-125
critical
9.8
2018-05-30 CVE-2018-11439 Out-of-bounds Read vulnerability in multiple products
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
network
low complexity
taglib debian CWE-125
6.5
2018-05-30 CVE-2018-11436 Out-of-bounds Read vulnerability in Libmobi Project Libmobi 0.3
The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
network
low complexity
libmobi-project CWE-125
6.5
2018-05-30 CVE-2018-11434 Out-of-bounds Read vulnerability in Libmobi Project Libmobi 0.3
The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
network
low complexity
libmobi-project CWE-125
6.5
2018-05-30 CVE-2018-11433 Out-of-bounds Read vulnerability in Libmobi Project Libmobi 0.3
The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
network
low complexity
libmobi-project CWE-125
6.5
2018-05-30 CVE-2018-11432 Out-of-bounds Read vulnerability in Libmobi Project Libmobi 0.3
The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
network
low complexity
libmobi-project CWE-125
6.5
2018-05-30 CVE-2018-11233 Out-of-bounds Read vulnerability in multiple products
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
network
low complexity
canonical git-scm CWE-125
7.5
2018-05-29 CVE-2018-11547 Out-of-bounds Read vulnerability in Md4C Project Md4C 0.2.5
md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.
network
low complexity
md4c-project CWE-125
critical
9.8