Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-15018 Out-of-bounds Read vulnerability in Lame Project Lame
LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.
4.3
2017-10-04 CVE-2017-0812 Out-of-bounds Read vulnerability in Google Android
An elevation of privilege vulnerability in the Android media framework (audio hal).
network
google CWE-125
critical
9.3
2017-10-02 CVE-2017-14976 Out-of-bounds Read vulnerability in multiple products
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.
network
low complexity
freedesktop debian CWE-125
5.0
2017-09-30 CVE-2017-14939 Out-of-bounds Read vulnerability in GNU Binutils 2.29
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.
local
low complexity
gnu CWE-125
5.5
2017-09-30 CVE-2017-14931 Out-of-bounds Read vulnerability in Openexif Project Openexif 2.1.4
ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted JPEG file.
4.3
2017-09-29 CVE-2017-14860 Out-of-bounds Read vulnerability in Exiv2 0.26
There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26.
network
exiv2 CWE-125
4.3
2017-09-28 CVE-2017-14795 Out-of-bounds Read vulnerability in Libbpg Project Libbpg 0.9.7
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with hls_pcm_sample in hevc.c in libavcodec in FFmpeg and put_pcm_var in hevcdsp_template.c in libavcodec in FFmpeg.
6.8
2017-09-25 CVE-2017-14733 Out-of-bounds Read vulnerability in multiple products
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
network
low complexity
graphicsmagick debian CWE-125
6.5
2017-09-25 CVE-2017-14731 Out-of-bounds Read vulnerability in Libofx Project Libofx 0.9.12
ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an ofxdump call.
4.3
2017-09-25 CVE-2015-5327 Out-of-bounds Read vulnerability in Linux Kernel 4.3
Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.
network
low complexity
linux CWE-125
4.0