Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-09-04 CVE-2018-16427 Out-of-bounds Read vulnerability in Opensc Project Opensc
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
local
low complexity
opensc-project CWE-125
2.1
2018-09-03 CVE-2018-16413 Out-of-bounds Read vulnerability in Imagemagick 7.0.811
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.
6.8
2018-09-03 CVE-2018-16412 Out-of-bounds Read vulnerability in multiple products
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
6.8
2018-09-03 CVE-2018-16403 Out-of-bounds Read vulnerability in Elfutils Project Elfutils 0.173
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.
local
low complexity
elfutils-project CWE-125
5.5
2018-09-03 CVE-2018-16382 Out-of-bounds Read vulnerability in Nasm Netwide Assembler 2.14
Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.
network
nasm CWE-125
4.3
2018-09-03 CVE-2018-16368 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
4.3
2018-09-02 CVE-2018-16336 Out-of-bounds Read vulnerability in multiple products
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
4.3
2018-09-01 CVE-2018-15161 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15160 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5
2018-09-01 CVE-2018-15159 Out-of-bounds Read vulnerability in Libesedb Project Libesedb 20180401
The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file.
network
low complexity
libesedb-project CWE-125
6.5