Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13305 Out-of-bounds Read vulnerability in multiple products
A information disclosure vulnerability in the Upstream kernel encrypted-keys.
local
low complexity
google canonical debian CWE-125
3.6
2018-04-04 CVE-2017-13290 Out-of-bounds Read vulnerability in Google Android
In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2018-04-04 CVE-2017-13280 Out-of-bounds Read vulnerability in Google Android
In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
5.0
2018-04-04 CVE-2017-13275 Out-of-bounds Read vulnerability in Google Android 8.0/8.1
In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check.
local
google CWE-125
1.9
2018-04-03 CVE-2018-5821 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_wow_wakeup_host_event(), wake_info->vdev_id is received from FW and is used directly as array index to access wma->interfaces whose max index should be (max_bssid-1).
network
low complexity
google CWE-125
7.5
2018-04-03 CVE-2017-15853 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app() is invoked without validating the packet length.
network
low complexity
google CWE-125
5.0
2018-04-03 CVE-2017-15837 Out-of-bounds Read vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_OFFSET is not defined which can lead to a buffer over-read in nla_get_u32().
network
low complexity
google CWE-125
5.0
2018-04-03 CVE-2018-4160 Out-of-bounds Read vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
apple CWE-125
critical
9.3
2018-04-03 CVE-2018-4136 Out-of-bounds Read vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
apple CWE-125
critical
9.3
2018-04-02 CVE-2018-6248 Out-of-bounds Read vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service or possible escalation of privileges.
local
low complexity
nvidia microsoft CWE-125
7.2