Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2017-08-04 CVE-2017-12452 Out-of-bounds Read vulnerability in GNU Binutils
The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted mach-o file.
local
low complexity
gnu CWE-125
7.8
2017-08-04 CVE-2017-12451 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a crafted COFF image file.
local
low complexity
gnu CWE-125
7.8
2017-08-04 CVE-2017-12449 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.
local
low complexity
gnu CWE-125
7.8
2017-08-02 CVE-2017-9770 Out-of-bounds Read vulnerability in Razerzone Razer Synapse
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.
local
low complexity
razerzone CWE-125
5.5
2017-08-02 CVE-2017-11334 Out-of-bounds Read vulnerability in multiple products
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
local
low complexity
qemu debian CWE-125
4.4
2017-08-02 CVE-2017-12142 Out-of-bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
ytnef-project CWE-125
5.5
2017-08-01 CVE-2017-12067 Out-of-bounds Read vulnerability in Potrace Project Potrace 1.14
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
network
low complexity
potrace-project CWE-125
7.5
2017-07-31 CVE-2017-11669 Out-of-bounds Read vulnerability in Eapmd5Pass Project Eapmd5Pass 1.4
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets.
network
low complexity
eapmd5pass-project CWE-125
7.5
2017-07-31 CVE-2017-11668 Out-of-bounds Read vulnerability in Eapmd5Pass Project Eapmd5Pass 1.4
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets.
network
low complexity
eapmd5pass-project CWE-125
7.5
2017-07-31 CVE-2017-11547 Out-of-bounds Read vulnerability in Timidity++ Project Timidity++ 2.14.0
The resample_gauss function in resample.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mid file.
local
low complexity
timidity-project CWE-125
5.5