Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-9283 Out-of-bounds Read vulnerability in Microfocus Visibroker 8.5
An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5.
network
low complexity
microfocus CWE-125
critical
9.8
2017-09-21 CVE-2017-7544 Out-of-bounds Read vulnerability in Libexif Project Libexif
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
network
low complexity
libexif-project CWE-125
6.4
2017-09-21 CVE-2017-14646 Out-of-bounds Read vulnerability in Axiosys Bento4 1.5.0617
The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.
network
low complexity
axiosys CWE-125
5.0
2017-09-21 CVE-2017-14645 Out-of-bounds Read vulnerability in Bento4 1.5.0617
A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617.
network
bento4 CWE-125
4.3
2017-09-21 CVE-2017-14643 Out-of-bounds Read vulnerability in Bento4 1.5.0617
The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4_BytesToUInt32BE in Core/Ap4Utils.h.
network
bento4 CWE-125
4.3
2017-09-21 CVE-2017-11002 Out-of-bounds Read vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
network
google CWE-125
4.3
2017-09-21 CVE-2017-14246 Out-of-bounds Read vulnerability in multiple products
An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
5.8
2017-09-21 CVE-2017-14245 Out-of-bounds Read vulnerability in multiple products
An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
5.8
2017-09-21 CVE-2017-14633 Out-of-bounds Read vulnerability in multiple products
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
4.3
2017-09-20 CVE-2017-14608 Out-of-bounds Read vulnerability in Libraw
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp.
network
low complexity
libraw CWE-125
6.4