CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,695)
This vulnerability allows attackers with privileged access on Linux non-secure operating systems to bypass memory length checks and leak sensitive dat...
Apr 5, 2024CVE-2021-41556 is a critical out-of-bounds read vulnerability in Squirrel scripting language that allows sandbox escape and arbitrary code execution. ...
Jul 28, 2022CVE-2021-21777 is a critical out-of-bounds read vulnerability in the Ethernet/IP UDP handler of OpENer EtherNet/IP stack. Attackers can send specially...
Jun 17, 2021A memory corruption vulnerability in Wasmtime's Cranelift code generator allows WebAssembly modules to read/write memory beyond their allocated bounds...
Mar 8, 2023This vulnerability in NetXDuo's DHCPv6 client allows attackers to cause out-of-bounds memory reads by sending specially crafted DHCPv6 packets. It aff...
Oct 20, 2025cJSON versions 1.5.0 through 1.7.18 contain an out-of-bounds access vulnerability in the decode_array_index_from_pointer function. This allows remote ...
Sep 3, 2025This vulnerability allows an attacker to perform out-of-bounds memory operations on JavaScript Promise objects, potentially leading to arbitrary code ...
May 17, 2025This CVE describes an out-of-bounds read vulnerability in macOS that could allow a malicious application to cause a system crash or unexpected termina...
Mar 31, 2025This is a macOS kernel memory disclosure vulnerability caused by insufficient bounds checking. An application could potentially read sensitive kernel ...
Mar 31, 2025This CVE describes an out-of-bounds read vulnerability in Apple's audio file processing that could allow unexpected app termination. Attackers could e...
Mar 31, 2025A critical heap buffer overflow vulnerability in CryptoLib versions 1.3.3 and prior allows attackers to cause denial of service or potentially execute...
Mar 17, 2025This critical vulnerability in macOS DCP firmware allows attackers to execute arbitrary code or cause system crashes through out-of-bounds memory acce...
Dec 12, 2024This vulnerability in LibJXL allows attackers to trigger out-of-bounds memory operations when processing untrusted JPEG files during JPEG XL recompres...
Nov 25, 2024This is a memory corruption vulnerability in the Linux kernel's tracing subsystem caused by an incorrect length check in the ftrace buffer. It allows ...
May 21, 2024FreeRDP clients prior to version 3.5.1 contain an out-of-bounds read vulnerability when processing remote desktop connections with zero width and heig...
Apr 23, 2024CVE-2024-32658 is an out-of-bounds read vulnerability in FreeRDP clients prior to version 3.5.1. This vulnerability could allow attackers to read sens...
Apr 23, 2024FreeRDP clients and servers running versions before 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability that could allow attackers to read sen...
Apr 22, 2024FreeRDP clients using versions before 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability in the graphics pipeline. This could allow attackers...
Apr 22, 2024FreeRDP clients prior to versions 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability (CWE-125) that could allow remote attackers to read sens...
Apr 22, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers via a stack overflow in the fromVirtualSer function. Attack...
Apr 17, 2024This CVE describes a stack overflow vulnerability in Tenda AC7V1.0 routers via the PPW parameter in the fromWizardHandle function. Attackers can explo...
Apr 17, 2024CVE-2024-23086 is a disputed vulnerability in Apfloat v1.10.1 where a stack overflow in the DoubleModMath::modPow method could potentially allow arbit...
Apr 8, 2024This CVE describes a buffer overflow vulnerability in the CSAPP Lab3 educational software component buflab-update.pl. A remote attacker can exploit th...
Apr 3, 2024CVE-2024-30630 is a critical stack overflow vulnerability in Tenda FH1205 routers that allows remote attackers to execute arbitrary code by sending sp...
Mar 29, 2024CVE-2024-30587 is a critical stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the 'urls' ...
Mar 28, 2024This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution by sending specially crafted data to the d...
Mar 28, 2024This vulnerability allows an attacker to perform out-of-bounds memory reads or writes on JavaScript objects by exploiting a flaw in Firefox's range-ba...
Mar 22, 2024This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code or cause denial of serv...
Mar 18, 2024This vulnerability allows remote attackers to execute arbitrary code on affected HP printers by sending specially crafted PDF files containing malicio...
Feb 20, 2024CVE-2023-46569 is an out-of-bounds read vulnerability in radare2's ND32 disassembler that could allow attackers to read sensitive memory contents or c...
Oct 28, 2023This CVE describes an out-of-bounds read vulnerability in Android's baseband firmware that could allow remote information disclosure. Attackers with b...
Oct 11, 2023CVE-2023-41910 is a critical heap memory out-of-bounds read vulnerability in lldpd network discovery daemon. Attackers can exploit this by sending spe...
Sep 5, 2023This CVE describes a critical kernel-level out-of-bounds read vulnerability in Apple operating systems. An attacker could exploit this to execute arbi...
Jul 28, 2023This is a critical buffer overflow vulnerability in Android's Bluetooth Low Energy (BLE) stack that allows remote code execution without user interact...
Jun 15, 2023This vulnerability allows attackers to read memory outside the intended bounds in the facial recognition Trusted Application (TA) of certain HarmonyOS...
May 26, 2023An off-by-one buffer overflow vulnerability in Contiki-NG's Antelope database system allows memory corruption when merging strings in storage function...
Apr 26, 2023CVE-2022-23123 is a critical out-of-bounds read vulnerability in Netatalk's getdirparams method that allows unauthenticated remote attackers to read s...
Mar 28, 2023This vulnerability is a read access violation in the III_dequantize_sample function of mp3gain's mpglibDBL library. It allows remote attackers to caus...
May 11, 2022CVE-2022-1276 is an out-of-bounds read vulnerability in mruby's mrb_get_args function that could allow attackers to read sensitive memory contents. If...
Apr 10, 2022A heap-based buffer overflow vulnerability in JerryScript 2.4.0 and earlier allows attackers to execute arbitrary code or cause denial of service via ...
Apr 7, 2022This is a critical out-of-bounds memory access vulnerability in Huawei smartphones that allows attackers to cause process exceptions or potentially ex...
Oct 28, 2021This critical Android vulnerability allows attackers to remotely execute code and gain elevated privileges on affected devices without user interactio...
Jun 21, 2021CVE-2021-33590 is a stack-based buffer over-read vulnerability in GattLib's get_device_path_from_mac function that allows reading beyond allocated mem...
May 27, 2021CVE-2021-1794 is a critical out-of-bounds read vulnerability in iOS/iPadOS that allows remote attackers to potentially execute arbitrary code on affec...
Apr 2, 2021This vulnerability allows remote attackers to execute arbitrary code on Synology DiskStation Manager (DSM) systems by sending specially crafted web re...
Mar 12, 2021This vulnerability is a critical memory corruption flaw in the WPG plugin for IrfanView image viewer. Attackers can exploit it by tricking users into ...
Feb 17, 2021This vulnerability in the xcb Rust crate allows out-of-bounds memory reads when using the change_property() function, potentially exposing sensitive d...
Feb 9, 2021CVE-2020-11212 is a critical out-of-bounds read vulnerability in Qualcomm Snapdragon chipsets that allows attackers to read memory beyond allocated bo...
Jan 21, 2021This CVE describes a buffer over-read vulnerability in Qualcomm audio drivers affecting numerous Snapdragon platforms. It allows attackers to read bey...
Jan 21, 2021This vulnerability in Ethernut's DNS implementation lacks proper null-termination checks for domain names, allowing attackers to trigger buffer overfl...
Dec 11, 2020About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,695 CVEs classified as CWE-125, with 145 rated critical and 1,002 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free