CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,695
Total CVEs
145
Critical
1,002
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 158
3 Google 147
4 Microsoft 113
5 Apple 86
6 Debian 80
7 Siemens 59
8 Pdf Xchange 58
9 Samsung 50
10 Fedoraproject 36

All Out-of-bounds Read CVEs (1,695)

CVE-2024-22004
10.0

This vulnerability allows attackers with privileged access on Linux non-secure operating systems to bypass memory length checks and leak sensitive dat...

Apr 5, 2024
CVE-2021-41556
10.0

CVE-2021-41556 is a critical out-of-bounds read vulnerability in Squirrel scripting language that allows sandbox escape and arbitrary code execution. ...

Jul 28, 2022
CVE-2021-21777
10.0

CVE-2021-21777 is a critical out-of-bounds read vulnerability in the Ethernet/IP UDP handler of OpENer EtherNet/IP stack. Attackers can send specially...

Jun 17, 2021
CVE-2023-26489
9.9

A memory corruption vulnerability in Wasmtime's Cranelift code generator allows WebAssembly modules to read/write memory beyond their allocated bounds...

Mar 8, 2023
CVE-2025-55086
9.8

This vulnerability in NetXDuo's DHCPv6 client allows attackers to cause out-of-bounds memory reads by sending specially crafted DHCPv6 packets. It aff...

Oct 20, 2025
CVE-2025-57052
9.8

cJSON versions 1.5.0 through 1.7.18 contain an out-of-bounds access vulnerability in the decode_array_index_from_pointer function. This allows remote ...

Sep 3, 2025
CVE-2025-4918
9.8

This vulnerability allows an attacker to perform out-of-bounds memory operations on JavaScript Promise objects, potentially leading to arbitrary code ...

May 17, 2025
CVE-2025-24265
9.8

This CVE describes an out-of-bounds read vulnerability in macOS that could allow a malicious application to cause a system crash or unexpected termina...

Mar 31, 2025
CVE-2025-24256
9.8

This is a macOS kernel memory disclosure vulnerability caused by insufficient bounds checking. An application could potentially read sensitive kernel ...

Mar 31, 2025
CVE-2025-24230
9.8

This CVE describes an out-of-bounds read vulnerability in Apple's audio file processing that could allow unexpected app termination. Attackers could e...

Mar 31, 2025
CVE-2025-29913
9.8

A critical heap buffer overflow vulnerability in CryptoLib versions 1.3.3 and prior allows attackers to cause denial of service or potentially execute...

Mar 17, 2025
CVE-2024-54506
9.8

This critical vulnerability in macOS DCP firmware allows attackers to execute arbitrary code or cause system crashes through out-of-bounds memory acce...

Dec 12, 2024
CVE-2024-11403
9.8

This vulnerability in LibJXL allows attackers to trigger out-of-bounds memory operations when processing untrusted JPEG files during JPEG XL recompres...

Nov 25, 2024
CVE-2021-47274
9.8

This is a memory corruption vulnerability in the Linux kernel's tracing subsystem caused by an incorrect length check in the ftrace buffer. It allows ...

May 21, 2024
CVE-2024-32659
9.8

FreeRDP clients prior to version 3.5.1 contain an out-of-bounds read vulnerability when processing remote desktop connections with zero width and heig...

Apr 23, 2024
CVE-2024-32658
9.8

CVE-2024-32658 is an out-of-bounds read vulnerability in FreeRDP clients prior to version 3.5.1. This vulnerability could allow attackers to read sens...

Apr 23, 2024
CVE-2024-32459
9.8

FreeRDP clients and servers running versions before 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability that could allow attackers to read sen...

Apr 22, 2024
CVE-2024-32041
9.8

FreeRDP clients using versions before 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability in the graphics pipeline. This could allow attackers...

Apr 22, 2024
CVE-2024-32458
9.8

FreeRDP clients prior to versions 3.5.0 or 2.11.6 contain an out-of-bounds read vulnerability (CWE-125) that could allow remote attackers to read sens...

Apr 22, 2024
CVE-2024-32286
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers via a stack overflow in the fromVirtualSer function. Attack...

Apr 17, 2024
CVE-2024-32301
9.8

This CVE describes a stack overflow vulnerability in Tenda AC7V1.0 routers via the PPW parameter in the fromWizardHandle function. Attackers can explo...

Apr 17, 2024
CVE-2024-23086
9.8

CVE-2024-23086 is a disputed vulnerability in Apfloat v1.10.1 where a stack overflow in the DoubleModMath::modPow method could potentially allow arbit...

Apr 8, 2024
CVE-2024-28515
9.8

This CVE describes a buffer overflow vulnerability in the CSAPP Lab3 educational software component buflab-update.pl. A remote attacker can exploit th...

Apr 3, 2024
CVE-2024-30630
9.8

CVE-2024-30630 is a critical stack overflow vulnerability in Tenda FH1205 routers that allows remote attackers to execute arbitrary code by sending sp...

Mar 29, 2024
CVE-2024-30587
9.8

CVE-2024-30587 is a critical stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the 'urls' ...

Mar 28, 2024
CVE-2024-30596
9.8

This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution by sending specially crafted data to the d...

Mar 28, 2024
CVE-2024-29943
9.8

This vulnerability allows an attacker to perform out-of-bounds memory reads or writes on JavaScript objects by exploiting a flaw in Firefox's range-ba...

Mar 22, 2024
CVE-2024-28537
9.8

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code or cause denial of serv...

Mar 18, 2024
CVE-2024-0794
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected HP printers by sending specially crafted PDF files containing malicio...

Feb 20, 2024
CVE-2023-46569
9.8

CVE-2023-46569 is an out-of-bounds read vulnerability in radare2's ND32 disassembler that could allow attackers to read sensitive memory contents or c...

Oct 28, 2023
CVE-2023-35648
9.8

This CVE describes an out-of-bounds read vulnerability in Android's baseband firmware that could allow remote information disclosure. Attackers with b...

Oct 11, 2023
CVE-2023-41910
9.8

CVE-2023-41910 is a critical heap memory out-of-bounds read vulnerability in lldpd network discovery daemon. Attackers can exploit this by sending spe...

Sep 5, 2023
CVE-2023-37285
9.8

This CVE describes a critical kernel-level out-of-bounds read vulnerability in Apple operating systems. An attacker could exploit this to execute arbi...

Jul 28, 2023
CVE-2023-21130
9.8

This is a critical buffer overflow vulnerability in Android's Bluetooth Low Energy (BLE) stack that allows remote code execution without user interact...

Jun 15, 2023
CVE-2022-48479
9.8

This vulnerability allows attackers to read memory outside the intended bounds in the facial recognition Trusted Application (TA) of certain HarmonyOS...

May 26, 2023
CVE-2023-30546
9.8

An off-by-one buffer overflow vulnerability in Contiki-NG's Antelope database system allows memory corruption when merging strings in storage function...

Apr 26, 2023
CVE-2022-23123
9.8

CVE-2022-23123 is a critical out-of-bounds read vulnerability in Netatalk's getdirparams method that allows unauthenticated remote attackers to read s...

Mar 28, 2023
CVE-2021-34085
9.8

This vulnerability is a read access violation in the III_dequantize_sample function of mp3gain's mpglibDBL library. It allows remote attackers to caus...

May 11, 2022
CVE-2022-1276
9.8

CVE-2022-1276 is an out-of-bounds read vulnerability in mruby's mrb_get_args function that could allow attackers to read sensitive memory contents. If...

Apr 10, 2022
CVE-2021-43453
9.8

A heap-based buffer overflow vulnerability in JerryScript 2.4.0 and earlier allows attackers to execute arbitrary code or cause denial of service via ...

Apr 7, 2022
CVE-2021-22474
9.8

This is a critical out-of-bounds memory access vulnerability in Huawei smartphones that allows attackers to cause process exceptions or potentially ex...

Oct 28, 2021
CVE-2021-0516
9.8

This critical Android vulnerability allows attackers to remotely execute code and gain elevated privileges on affected devices without user interactio...

Jun 21, 2021
CVE-2021-33590
9.8

CVE-2021-33590 is a stack-based buffer over-read vulnerability in GattLib's get_device_path_from_mac function that allows reading beyond allocated mem...

May 27, 2021
CVE-2021-1794
9.8

CVE-2021-1794 is a critical out-of-bounds read vulnerability in iOS/iPadOS that allows remote attackers to potentially execute arbitrary code on affec...

Apr 2, 2021
CVE-2021-27647
9.8

This vulnerability allows remote attackers to execute arbitrary code on Synology DiskStation Manager (DSM) systems by sending specially crafted web re...

Mar 12, 2021
CVE-2021-27362
9.8

This vulnerability is a critical memory corruption flaw in the WPG plugin for IrfanView image viewer. Attackers can exploit it by tricking users into ...

Feb 17, 2021
CVE-2021-26957
9.8

This vulnerability in the xcb Rust crate allows out-of-bounds memory reads when using the change_property() function, potentially exposing sensitive d...

Feb 9, 2021
CVE-2020-11212
9.8

CVE-2020-11212 is a critical out-of-bounds read vulnerability in Qualcomm Snapdragon chipsets that allows attackers to read memory beyond allocated bo...

Jan 21, 2021
CVE-2020-11136
9.8

This CVE describes a buffer over-read vulnerability in Qualcomm audio drivers affecting numerous Snapdragon platforms. It allows attackers to read bey...

Jan 21, 2021
CVE-2020-25107
9.8

This vulnerability in Ethernut's DNS implementation lacks proper null-termination checks for domain names, allowing attackers to trigger buffer overfl...

Dec 11, 2020

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,695 CVEs classified as CWE-125, with 145 rated critical and 1,002 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free