Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2017-09-14 CVE-2017-12897 Out-of-bounds Read vulnerability in Tcpdump
The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-12896 Out-of-bounds Read vulnerability in multiple products
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
network
low complexity
tcpdump debian redhat CWE-125
7.5
2017-09-14 CVE-2017-12895 Out-of-bounds Read vulnerability in Tcpdump
The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-12894 Out-of-bounds Read vulnerability in Tcpdump
Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-12893 Out-of-bounds Read vulnerability in Tcpdump
The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().
network
low complexity
tcpdump CWE-125
7.5
2017-09-13 CVE-2017-14410 Out-of-bounds Read vulnerability in Mp3Gain 1.5.2
A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2.
network
mp3gain CWE-125
4.3
2017-09-13 CVE-2017-14408 Out-of-bounds Read vulnerability in Mp3Gain 1.5.2
A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2.
network
mp3gain CWE-125
4.3
2017-09-13 CVE-2017-14407 Out-of-bounds Read vulnerability in Mp3Gain 1.5.2
A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2.
network
mp3gain CWE-125
4.3
2017-09-12 CVE-2017-14316 Out-of-bounds Read vulnerability in XEN
A parameter verification issue was discovered in Xen through 4.9.x.
local
low complexity
xen CWE-125
7.2
2017-09-12 CVE-2017-14314 Out-of-bounds Read vulnerability in multiple products
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.
4.3