Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-03-14 CVE-2018-8106 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-14 CVE-2018-8105 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-14 CVE-2018-8104 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-14 CVE-2018-8103 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-14 CVE-2018-8102 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-14 CVE-2018-8101 Out-of-bounds Read vulnerability in Xpdfreader Xpdf 4.00
The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4.3
2018-03-13 CVE-2018-1000085 Out-of-bounds Read vulnerability in multiple products
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains..
4.3
2018-03-12 CVE-2018-7858 Out-of-bounds Read vulnerability in multiple products
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
local
low complexity
qemu opensuse redhat canonical CWE-125
2.1
2018-03-12 CVE-2016-9953 Out-of-bounds Read vulnerability in Haxx Curl
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.
network
low complexity
haxx CWE-125
critical
9.8
2018-03-12 CVE-2017-6288 Out-of-bounds Read vulnerability in Google Android
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure.
local
low complexity
google CWE-125
2.1