CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,726
Total CVEs
157
Critical
1,021
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 150
4 Microsoft 113
5 Apple 90
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,726)

CVE-2023-26085
7.8

CVE-2023-26085 is an out-of-bounds read/write vulnerability in Arm NN Android-NN-Driver due to improper shared memory length validation. This allows a...

Jun 29, 2023
CVE-2023-25003
7.8

This vulnerability in Autodesk AutoCAD 2023 and Maya 2022 allows attackers to execute arbitrary code by exploiting out-of-bounds read/write vulnerabil...

Jun 23, 2023
CVE-2023-31239
7.8

A stack-based buffer overflow vulnerability in Fuji Electric V-Server and V-Server Lite SCADA software allows remote code execution when a user opens ...

Jun 19, 2023
CVE-2023-32017
7.8

This vulnerability allows remote code execution through the Microsoft PostScript Printer Driver. Attackers can exploit it by sending specially crafted...

Jun 14, 2023
CVE-2023-32029
7.8

CVE-2023-32029 is a remote code execution vulnerability in Microsoft Excel that allows attackers to execute arbitrary code by tricking users into open...

Jun 14, 2023
CVE-2023-33123
7.8

This vulnerability allows remote code execution through specially crafted CGM files in Siemens JT2Go and Teamcenter Visualization software. An attacke...

Jun 13, 2023
CVE-2023-27916
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting improper validation in font file parsing. It affects applications that pro...

Jun 6, 2023
CVE-2023-32289
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing project files. It affects industrial co...

Jun 6, 2023
CVE-2023-32545
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting improper input validation in Cscape project file parsing. An attacker can ...

Jun 6, 2023
CVE-2023-29280
7.8

Adobe Substance 3D Painter versions 8.3.0 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker can exploi...

May 11, 2023
CVE-2023-29273
7.8

Adobe Substance 3D Painter versions 8.3.0 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. This could allow attac...

May 11, 2023
CVE-2023-29275
7.8

Adobe Substance 3D Painter has an out-of-bounds read vulnerability that could allow an attacker to execute arbitrary code on a victim's system. Users ...

May 11, 2023
CVE-2023-29460
7.8

A memory buffer overflow vulnerability in Rockwell Automation's Arena Simulation software allows arbitrary code execution. This could let attackers ru...

May 9, 2023
CVE-2023-27938
7.8

This vulnerability in GarageBand for macOS allows attackers to execute arbitrary code or cause application crashes by tricking users into opening mali...

May 8, 2023
CVE-2023-27946
7.8

CVE-2023-27946 is an out-of-bounds read vulnerability in Apple operating systems that could allow arbitrary code execution when processing malicious f...

May 8, 2023
CVE-2023-27906
7.8

This vulnerability allows attackers to execute arbitrary code by tricking victims into opening malicious USD (Universal Scene Description) files. It a...

Apr 17, 2023
CVE-2023-27912
7.8

This vulnerability in Autodesk AutoCAD 2023 allows attackers to exploit an out-of-bounds read when processing malicious X_B files. Successful exploita...

Apr 14, 2023
CVE-2023-26409
7.8

Adobe Substance 3D Designer versions 12.4.0 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker can expl...

Apr 13, 2023
CVE-2023-26411
7.8

Adobe Substance 3D Designer versions 12.4.0 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could ex...

Apr 13, 2023
CVE-2023-26425
7.8

Adobe Acrobat Reader versions 23.001.20093 and earlier, and 20.005.30441 and earlier, contain an out-of-bounds read vulnerability when parsing malicio...

Apr 12, 2023
CVE-2023-29053
7.8

This vulnerability allows remote code execution through specially crafted JT files in JT Open and JT Utilities software. Attackers can exploit an out-...

Apr 11, 2023
CVE-2022-43616
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EMF image files in CorelDRAW Graphics Su...

Mar 29, 2023
CVE-2022-37366
7.8

CVE-2022-37366 is a remote code execution vulnerability in PDF-XChange Editor that allows attackers to execute arbitrary code by tricking users into o...

Mar 29, 2023
CVE-2022-37350
7.8

CVE-2022-37350 is a buffer overflow vulnerability in PDF-XChange Editor's handling of Collab objects that allows remote code execution. Attackers can ...

Mar 29, 2023
CVE-2022-28307
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in Bentley View. The flaw is a...

Mar 29, 2023
CVE-2023-25907
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker can exploit this to e...

Mar 28, 2023
CVE-2023-26327
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. T...

Mar 28, 2023
CVE-2023-26329
7.8

CVE-2023-26329 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory, potentially bypassing ...

Mar 28, 2023
CVE-2023-26331
7.8

CVE-2023-26331 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory information. This could...

Mar 28, 2023
CVE-2023-26333
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker can exploit this to e...

Mar 28, 2023
CVE-2023-26335
7.8

CVE-2023-26335 is an out-of-bounds read vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a malicious file....

Mar 28, 2023
CVE-2023-25891
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this to...

Mar 28, 2023
CVE-2023-25887
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. This could allow an attacker to e...

Mar 28, 2023
CVE-2023-25889
7.8

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. This could allow an attacker to e...

Mar 28, 2023
CVE-2022-24907
7.8

CVE-2022-24907 is a buffer overflow vulnerability in Foxit PDF Reader's JP2 image parser that allows remote code execution. Attackers can exploit this...

Mar 28, 2023
CVE-2023-25863
7.8

Adobe Substance 3D Stager has an out-of-bounds read vulnerability when parsing malicious files, which could allow attackers to execute arbitrary code ...

Mar 27, 2023
CVE-2023-25869
7.8

Adobe Substance 3D Stager has an out-of-bounds read vulnerability that could allow arbitrary code execution when a user opens a malicious file. Attack...

Mar 27, 2023
CVE-2023-25873
7.8

Adobe Substance 3D Stager has an out-of-bounds read vulnerability when parsing malicious files, which could allow attackers to execute arbitrary code ...

Mar 27, 2023
CVE-2023-23399
7.8

CVE-2023-23399 is a remote code execution vulnerability in Microsoft Excel that allows attackers to execute arbitrary code by tricking users into open...

Mar 14, 2023
CVE-2023-27402
7.8

This vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing maliciou...

Mar 14, 2023
CVE-2023-22419
7.8

This vulnerability allows attackers to execute arbitrary code or disclose sensitive information by tricking users into opening malicious project files...

Mar 6, 2023
CVE-2023-25140
7.8

This vulnerability allows remote code execution through specially crafted PAR files in Siemens Parasolid and Solid Edge software. An attacker can expl...

Feb 14, 2023
CVE-2023-24552
7.8

An out-of-bounds read vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files. This ...

Feb 14, 2023
CVE-2023-24554
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read vulnerability in Solid Edge's PAR file parser. Attac...

Feb 14, 2023
CVE-2023-24556
7.8

This vulnerability allows remote code execution through specially crafted PAR files in Solid Edge CAD software. Attackers can exploit an out-of-bounds...

Feb 14, 2023
CVE-2023-24558
7.8

This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PAR files. It a...

Feb 14, 2023
CVE-2023-22349
7.8

This CVE describes an out-of-bound read vulnerability in Screen Creator Advance 2 software that occurs when processing screen management information. ...

Feb 13, 2023
CVE-2023-22353
7.8

This CVE describes an out-of-bounds read vulnerability in Screen Creator Advance 2 software versions 0.1.1.4 Build01 and earlier. Attackers can exploi...

Feb 13, 2023
CVE-2023-22346
7.8

An out-of-bounds read vulnerability in Screen Creator Advance 2 allows attackers to craft malicious project files that, when opened by users, can lead...

Feb 13, 2023
CVE-2022-27866
7.8

CVE-2022-27866 is an out-of-bounds read vulnerability in Autodesk Design Review's TIFF file parser. Attackers can craft malicious TIFF files that caus...

Jul 29, 2022

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,726 CVEs classified as CWE-125, with 157 rated critical and 1,021 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free