CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,716
Total CVEs
151
Critical
1,017
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 87
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,716)

CVE-2024-27335
7.8

This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files. The flaw e...

Apr 3, 2024
CVE-2024-30359
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Apr 2, 2024
CVE-2024-30353
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Apr 2, 2024
CVE-2024-30341
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Apr 2, 2024
CVE-2024-0071
7.8

This vulnerability in NVIDIA GPU Display Driver for Windows allows an unprivileged user to perform an out-of-bounds write, potentially leading to code...

Mar 27, 2024
CVE-2024-25992
7.8

CVE-2024-25992 is an out-of-bounds read vulnerability in the tmu_tz_control function of tmu.c that allows local privilege escalation without user inte...

Mar 11, 2024
CVE-2024-26608
7.8

CVE-2024-26608 is a global out-of-bounds read vulnerability in the Linux kernel's ksmbd (SMB server) component. It allows attackers to read kernel mem...

Mar 11, 2024
CVE-2024-23258
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read when processing malicious images. It affects Apple v...

Mar 8, 2024
CVE-2024-1453
7.8

This vulnerability in Sante DICOM Viewer Pro allows attackers to execute arbitrary code or disclose information by tricking users into opening malicio...

Mar 1, 2024
CVE-2024-20750
7.8

CVE-2024-20750 is an out-of-bounds read vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious ...

Feb 15, 2024
CVE-2024-20742
7.8

CVE-2024-20742 is an out-of-bounds read vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a malicious f...

Feb 15, 2024
CVE-2024-24923
7.8

This vulnerability allows remote code execution through specially crafted Catia MODEL files in Simcenter Femap. Attackers can exploit an out-of-bounds...

Feb 13, 2024
CVE-2024-23802
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation software. Attackers can exploit an ...

Feb 13, 2024
CVE-2023-49125
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read in Parasolid and Solid Edge when processing maliciou...

Feb 13, 2024
CVE-2023-6040
7.8

This vulnerability allows attackers to achieve out-of-bounds memory access by creating netfilter tables with invalid protocol family values. It affect...

Jan 12, 2024
CVE-2024-20658
7.8

This vulnerability allows an authenticated attacker to gain SYSTEM privileges by exploiting a flaw in Microsoft's Virtual Hard Disk driver. It affects...

Jan 9, 2024
CVE-2023-47074
7.8

Adobe Illustrator versions 28.0 and earlier (and 27.9 and earlier) contain an out-of-bounds read vulnerability when parsing malicious files. This coul...

Dec 13, 2023
CVE-2023-42886
7.8

This CVE-2023-42886 is an out-of-bounds read vulnerability in macOS that could allow a user to cause unexpected app termination or arbitrary code exec...

Dec 12, 2023
CVE-2023-47066
7.8

Adobe After Effects versions 24.0.2 and earlier, and 23.6 and earlier, contain an out-of-bounds read vulnerability when parsing malicious files. This ...

Nov 17, 2023
CVE-2023-47068
7.8

Adobe After Effects has an out-of-bounds read vulnerability that could allow arbitrary code execution when a user opens a malicious file. Attackers co...

Nov 17, 2023
CVE-2023-47058
7.8

Adobe Premiere Pro versions 24.0 and earlier, and 23.6 and earlier, contain an out-of-bounds read vulnerability when parsing malicious files. An attac...

Nov 16, 2023
CVE-2023-26368
7.8

Adobe InCopy has an out-of-bounds read vulnerability that could allow arbitrary code execution when a user opens a malicious file. Attackers could exp...

Nov 16, 2023
CVE-2023-47040
7.8

Adobe Media Encoder versions 24.0.2 and earlier, and 23.6 and earlier, contain an out-of-bounds read vulnerability when parsing malicious files. An at...

Nov 16, 2023
CVE-2023-44338
7.8

Adobe Acrobat Reader versions 23.006.20360 and earlier, and 20.005.30524 and earlier, contain an out-of-bounds read vulnerability when parsing malicio...

Nov 16, 2023
CVE-2023-36424
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM-level privileges through a loca...

Nov 14, 2023
CVE-2023-21372
7.8

CVE-2023-21372 is an out-of-bounds read vulnerability in Android's libdexfile component that allows local privilege escalation without user interactio...

Oct 30, 2023
CVE-2023-27854
7.8

A memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software allows arbitrary code execution when a user opens a malicious ...

Oct 27, 2023
CVE-2023-39936
7.8

Ashlar-Vellum Graphite v13.0.48 has an out-of-bounds read vulnerability when parsing VC6 files due to improper input validation. This allows attackers...

Oct 26, 2023
CVE-2023-36701
7.8

This vulnerability allows an authenticated attacker to gain SYSTEM-level privileges on Windows systems using Microsoft's Resilient File System (ReFS)....

Oct 10, 2023
CVE-2023-44084
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Oct 10, 2023
CVE-2023-44086
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation software. Attackers can exploit an ...

Oct 10, 2023
CVE-2023-36766
7.8

CVE-2023-36766 is a Microsoft Excel information disclosure vulnerability that allows an attacker to read memory contents from the Excel process. This ...

Sep 12, 2023
CVE-2020-36615
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing a malicious font file. It affects macOS systems before...

Aug 14, 2023
CVE-2023-39187
7.8

This vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious DFT file...

Aug 8, 2023
CVE-2023-39185
7.8

An out-of-bounds read vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...

Aug 8, 2023
CVE-2023-39183
7.8

This vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PSM file...

Aug 8, 2023
CVE-2023-38529
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read vulnerability in Parasolid and Teamcenter Visualizat...

Aug 8, 2023
CVE-2023-38531
7.8

This vulnerability allows remote code execution through specially crafted X_T files in Siemens Parasolid and Teamcenter Visualization software. An att...

Aug 8, 2023
CVE-2023-38682
7.8

This vulnerability allows remote code execution through specially crafted TIFF files in Siemens JT2Go and Teamcenter Visualization software. An attack...

Aug 8, 2023
CVE-2023-30796
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Open and JT Utilities software. Attackers can exploit...

Aug 8, 2023
CVE-2023-38525
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read vulnerability when parsing specially crafted X_T fil...

Aug 8, 2023
CVE-2023-38527
7.8

This vulnerability allows remote code execution through specially crafted X_T files in Siemens Parasolid and Teamcenter Visualization software. An att...

Aug 8, 2023
CVE-2023-35358
7.8

This Windows kernel vulnerability allows attackers to gain elevated system privileges by exploiting improper memory handling. It affects Windows syste...

Jul 11, 2023
CVE-2023-35299
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM-level privileges through a loca...

Jul 11, 2023
CVE-2023-26085
7.8

CVE-2023-26085 is an out-of-bounds read/write vulnerability in Arm NN Android-NN-Driver due to improper shared memory length validation. This allows a...

Jun 29, 2023
CVE-2023-25003
7.8

This vulnerability in Autodesk AutoCAD 2023 and Maya 2022 allows attackers to execute arbitrary code by exploiting out-of-bounds read/write vulnerabil...

Jun 23, 2023
CVE-2023-31239
7.8

A stack-based buffer overflow vulnerability in Fuji Electric V-Server and V-Server Lite SCADA software allows remote code execution when a user opens ...

Jun 19, 2023
CVE-2023-32017
7.8

This vulnerability allows remote code execution through the Microsoft PostScript Printer Driver. Attackers can exploit it by sending specially crafted...

Jun 14, 2023
CVE-2023-32029
7.8

CVE-2023-32029 is a remote code execution vulnerability in Microsoft Excel that allows attackers to execute arbitrary code by tricking users into open...

Jun 14, 2023
CVE-2023-33123
7.8

This vulnerability allows remote code execution through specially crafted CGM files in Siemens JT2Go and Teamcenter Visualization software. An attacke...

Jun 13, 2023

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,716 CVEs classified as CWE-125, with 151 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free