| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |
| A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability. |
| The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85. |
| do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. |
| An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow. |
| Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. |
| A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. |
| A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d. |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a denial of service due to a heap-based out-of-bounds read. A remote attacker could send a specially crafted request that causes a limited out‑of‑bounds memory read. |
| A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. |
| An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption. |
| In the Linux kernel, the following vulnerability has been resolved:
ipvs: fix reversed sequence option serialization
hton_seq() expects the host-order source first and the unaligned
network-order destination second. The version 1 sync sender passes these
arguments in reverse for both sequence blocks. This leaves 24 bytes of the
kmalloc-backed message unwritten. It may disclose stale heap data and
replace the live connection sequence state with values read from the
buffer.
Pass the connection sequence state as the source and the message payload as
the destination for both blocks. |
| A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE. |
| IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service. |
| In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file. |
| In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: check A-MSDU format more carefully
If it looks like there's another subframe in the A-MSDU
but the header isn't fully there, we can end up reading
data out of bounds, only to discard later. Make this a
bit more careful and check if the subframe header can
even be present. |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to buffer overflow. |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or worker in applications that wait for additional bytes after IncompleteBufferError. There is no adjacent-memory disclosure because the buffer implementation checks bounds. This issue is fixed in version 6.1.0. |
| Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |