Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13259 Out-of-bounds Read vulnerability in Google Android
In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks.
network
low complexity
google CWE-125
5.0
2018-04-04 CVE-2017-13258 Out-of-bounds Read vulnerability in Google Android
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
5.0
2018-04-04 CVE-2017-13305 Out-of-bounds Read vulnerability in multiple products
A information disclosure vulnerability in the Upstream kernel encrypted-keys.
local
low complexity
google canonical debian CWE-125
3.6
2018-04-04 CVE-2017-13290 Out-of-bounds Read vulnerability in Google Android
In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2018-04-04 CVE-2017-13280 Out-of-bounds Read vulnerability in Google Android
In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
5.0
2018-04-04 CVE-2017-13275 Out-of-bounds Read vulnerability in Google Android 8.0/8.1
In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check.
local
google CWE-125
1.9
2018-04-03 CVE-2018-5821 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_wow_wakeup_host_event(), wake_info->vdev_id is received from FW and is used directly as array index to access wma->interfaces whose max index should be (max_bssid-1).
network
low complexity
google CWE-125
7.5
2018-04-03 CVE-2017-15853 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app() is invoked without validating the packet length.
network
low complexity
google CWE-125
5.0
2018-04-03 CVE-2017-15837 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_OFFSET is not defined which can lead to a buffer over-read in nla_get_u32().
network
low complexity
google CWE-125
5.0
2018-04-03 CVE-2018-4160 Out-of-bounds Read vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
apple CWE-125
critical
9.3