Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2017-8256 Out-of-bounds Read vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 multicast addresses.
local
low complexity
google CWE-125
7.8
2017-08-18 CVE-2015-9050 Out-of-bounds Read vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur during a CA call.
network
low complexity
google CWE-125
critical
9.8
2017-08-18 CVE-2017-9454 Out-of-bounds Read vulnerability in Resiprocate
Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response.
network
low complexity
resiprocate CWE-125
7.5
2017-08-18 CVE-2017-12941 Out-of-bounds Read vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
network
low complexity
rarlab CWE-125
critical
9.8
2017-08-18 CVE-2017-12940 Out-of-bounds Read vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
network
low complexity
rarlab CWE-125
critical
9.8
2017-08-18 CVE-2017-12937 Out-of-bounds Read vulnerability in multiple products
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
network
low complexity
graphicsmagick debian CWE-125
8.8
2017-08-18 CVE-2017-12935 Out-of-bounds Read vulnerability in multiple products
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
network
low complexity
graphicsmagick debian CWE-125
8.8
2017-08-18 CVE-2017-12933 Out-of-bounds Read vulnerability in PHP
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data.
network
low complexity
php CWE-125
critical
9.8
2017-08-17 CVE-2017-12445 Out-of-bounds Read vulnerability in Minidjvu Project Minidjvu 0.8
The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
network
low complexity
minidjvu-project CWE-125
6.5
2017-08-17 CVE-2017-12444 Out-of-bounds Read vulnerability in Minidjvu Project Minidjvu 0.8
The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
network
low complexity
minidjvu-project CWE-125
6.5