CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,729
Total CVEs
157
Critical
1,024
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 150
4 Microsoft 113
5 Apple 90
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,729)

CVE-2022-27866
7.8

CVE-2022-27866 is an out-of-bounds read vulnerability in Autodesk Design Review's TIFF file parser. Attackers can craft malicious TIFF files that caus...

Jul 29, 2022
CVE-2022-33881
7.8

This vulnerability allows attackers to craft malicious PRT files that cause Autodesk AutoCAD 2023 to read beyond allocated memory boundaries. When com...

Jul 29, 2022
CVE-2022-35672
7.8

This vulnerability in Adobe Acrobat Reader allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

Jul 27, 2022
CVE-2022-28682
7.8

This is a remote code execution vulnerability in Foxit PDF Reader that allows attackers to execute arbitrary code by tricking users into opening malic...

Jul 18, 2022
CVE-2022-28807
7.8

An out-of-bounds read vulnerability in Open Design Alliance Drawings SDK allows attackers to execute arbitrary code when processing malicious DWG file...

Jul 17, 2022
CVE-2022-34215
7.8

Adobe Acrobat Reader versions 22.001.20142 and earlier, 20.005.30334 and earlier, and 17.012.30229 and earlier contain an out-of-bounds read vulnerabi...

Jul 15, 2022
CVE-2022-34222
7.8

This vulnerability in Adobe Acrobat Reader allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

Jul 15, 2022
CVE-2021-26384
7.8

CVE-2021-26384 is an AMD CPU vulnerability where a malformed System Management Interface (SMI) command can corrupt SMI Trigger Info data structures, p...

Jul 14, 2022
CVE-2022-2206
7.8

CVE-2022-2206 is an out-of-bounds read vulnerability in Vim text editor versions prior to 8.2. This allows attackers to read sensitive memory contents...

Jun 26, 2022
CVE-2022-27531
7.8

This vulnerability allows a maliciously crafted TIF file to cause Autodesk 3ds Max to read beyond allocated memory boundaries. If exploited in conjunc...

Jun 16, 2022
CVE-2022-30549
7.8

This CVE describes an out-of-bounds read vulnerability in Fuji Electric's V-Server and V-Server Lite software that could allow attackers to read sensi...

Jun 16, 2022
CVE-2022-29506
7.8

This vulnerability allows attackers to read memory beyond intended boundaries in V-SFT graphic editor's simulator module. By tricking a user into open...

Jun 14, 2022
CVE-2022-32200
7.8

CVE-2022-32200 is a heap-based buffer over-read vulnerability in libdwarf 0.4.0's _dwarf_check_string_valid function in dwarf_util.c. This allows atta...

Jun 2, 2022
CVE-2022-29488
7.8

CVE-2022-29488 is an out-of-bounds read vulnerability via uninitialized pointer in industrial control systems software. This could allow attackers to ...

Jun 2, 2022
CVE-2022-26770
7.8

This CVE-2022-26770 is an out-of-bounds read vulnerability in macOS that allows malicious applications to execute arbitrary code with kernel privilege...

May 26, 2022
CVE-2022-26718
7.8

CVE-2022-26718 is an out-of-bounds read vulnerability in macOS that could allow an application to read memory beyond allocated boundaries. If exploite...

May 26, 2022
CVE-2022-28274
7.8

Adobe Photoshop versions 22.5.6 and earlier and 23.2.2 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attack...

May 6, 2022
CVE-2022-1402
7.8

CVE-2022-1402 is an out-of-bounds read vulnerability in ASDA-Soft versions 5.4.1.0 and earlier. Attackers can exploit this by tricking users into open...

Apr 29, 2022
CVE-2022-1427
7.8

CVE-2022-1427 is an out-of-bounds read vulnerability in mrb_obj_is_kind_of function in mruby, a lightweight Ruby implementation. This could allow atta...

Apr 23, 2022
CVE-2022-25794
7.8

An out-of-bounds read vulnerability in Autodesk FBX Review version 1.5.2 and earlier allows attackers to execute arbitrary code or disclose informatio...

Apr 11, 2022
CVE-2021-26623
7.8

A remote code execution vulnerability exists in the ark library due to insufficient validation of parameter length in the xheader_decode_path_record f...

Apr 1, 2022
CVE-2021-35106
7.8

This vulnerability allows attackers to read memory beyond intended boundaries in Qualcomm Snapdragon chipsets due to improper WMI message length calcu...

Apr 1, 2022
CVE-2022-27940
7.8

CVE-2022-27940 is a heap-based buffer over-read vulnerability in tcprewrite component of Tcpreplay 4.4.1. This allows attackers to read sensitive memo...

Mar 26, 2022
CVE-2022-27942
7.8

CVE-2022-27942 is a heap-based buffer over-read vulnerability in tcpprep utility of Tcpreplay 4.4.1. This allows attackers to read sensitive memory co...

Mar 26, 2022
CVE-2022-22601
7.8

CVE-2022-22601 is an out-of-bounds read vulnerability in Xcode that could allow arbitrary code execution when opening malicious files. This affects de...

Mar 18, 2022
CVE-2022-22603
7.8

CVE-2022-22603 is an out-of-bounds read vulnerability in Apple's Xcode development environment that could allow arbitrary code execution when opening ...

Mar 18, 2022
CVE-2022-22605
7.8

CVE-2022-22605 is an out-of-bounds read vulnerability in Xcode that could allow arbitrary code execution when opening malicious files. This affects de...

Mar 18, 2022
CVE-2022-22607
7.8

CVE-2022-22607 is an out-of-bounds read vulnerability in Xcode that could allow arbitrary code execution when opening malicious files. This affects de...

Mar 18, 2022
CVE-2021-42720
7.8

Adobe Bridge versions 11.1.1 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this to e...

Mar 16, 2022
CVE-2022-21219
7.8

This vulnerability allows attackers to read memory outside intended boundaries by tricking users into opening malicious CXP files in CX-Programmer. Su...

Mar 10, 2022
CVE-2022-21209
7.8

CVE-2022-21209 is an out-of-bounds read vulnerability in certain industrial control system (ICS) software that processes project files. An attacker ca...

Feb 25, 2022
CVE-2021-46619
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Bentley MicroStation CONNEC...

Feb 18, 2022
CVE-2021-46612
7.8

CVE-2021-46612 is an out-of-bounds read vulnerability in Bentley MicroStation CONNECT's PDF parser that allows remote code execution. Attackers can ex...

Feb 18, 2022
CVE-2021-46614
7.8

This vulnerability in Bentley MicroStation CONNECT allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K imag...

Feb 18, 2022
CVE-2021-46590
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious JT files. Attacker...

Feb 18, 2022
CVE-2021-46562
7.8

CVE-2021-46562 is an out-of-bounds read vulnerability in Bentley MicroStation CONNECT's JT file parser that allows remote code execution. Attackers ca...

Feb 18, 2022
CVE-2021-44018
7.8

A memory corruption vulnerability in Siemens JT2Go, Solid Edge, and Teamcenter Visualization products allows attackers to execute arbitrary code by tr...

Feb 9, 2022
CVE-2021-40158
7.8

This vulnerability allows a malicious JT file to cause Autodesk Inventor and AutoCAD to read beyond allocated memory boundaries. When combined with ot...

Jan 25, 2022
CVE-2021-40167
7.8

This vulnerability allows memory corruption through specially crafted DWF or PCT files when opened in Autodesk Design Review. Attackers could potentia...

Jan 25, 2022
CVE-2021-45060
7.8

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader DC that could allow an attacker to execute arbitrary code in the contex...

Jan 14, 2022
CVE-2021-34927
7.8

CVE-2021-34927 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit this by tr...

Jan 13, 2022
CVE-2021-34913
7.8

CVE-2021-34913 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit it by tric...

Jan 13, 2022
CVE-2021-34880
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious 3DS files in Bentley View. It affects us...

Jan 13, 2022
CVE-2021-34885
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JT files in Bentley View. The flaw exist...

Jan 13, 2022
CVE-2021-34858
7.8

This vulnerability allows remote attackers to execute arbitrary code on TeamViewer installations by tricking users into opening malicious TVS files. T...

Jan 13, 2022
CVE-2021-45055
7.8

Adobe InCopy versions 16.4 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker can exploit this to execu...

Jan 13, 2022
CVE-2021-40160
7.8

CVE-2021-40160 is an out-of-bounds read vulnerability in PDFTron PDF parsing libraries prior to version 9.0.7. Attackers can exploit this by crafting ...

Dec 23, 2021
CVE-2021-45469
7.8

This vulnerability allows an attacker to trigger an out-of-bounds memory access in the Linux kernel's F2FS filesystem when processing extended attribu...

Dec 23, 2021
CVE-2021-44859
7.8

An out-of-bounds read vulnerability in Open Design Alliance Drawings SDK allows attackers to execute arbitrary code by providing a malicious TGA file....

Dec 21, 2021
CVE-2021-44439
7.8

This vulnerability allows attackers to read memory beyond allocated buffers when parsing malicious JT files using JT Utilities or JTTK libraries. It a...

Dec 14, 2021

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,729 CVEs classified as CWE-125, with 157 rated critical and 1,024 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free