CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,835
Total CVEs
193
Critical
1,094
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 172
3 Google 162
4 Microsoft 113
5 Apple 109
6 Debian 91
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 48

All Out-of-bounds Read CVEs (1,835)

CVE-2021-40155
7.8

This vulnerability allows arbitrary code execution through maliciously crafted DWG files in Autodesk Navisworks. Attackers can exploit an out-of-bound...

Sep 15, 2021
CVE-2021-1952
7.8

A buffer over-read vulnerability in Qualcomm Snapdragon chipsets allows attackers to read memory beyond allocated buffers due to insufficient length v...

Sep 9, 2021
CVE-2021-1885
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing a maliciously crafted image. It affects Apple devices ...

Sep 8, 2021
CVE-2021-30752
7.8

This vulnerability allows arbitrary code execution when processing malicious images due to an out-of-bounds read. It affects Apple devices running vul...

Sep 8, 2021
CVE-2021-39258
7.8

CVE-2021-39258 is an out-of-bounds read vulnerability in NTFS-3G that allows attackers to read sensitive memory contents from a crafted NTFS image. Th...

Sep 7, 2021
CVE-2021-39252
7.8

CVE-2021-39252 is an out-of-bounds read vulnerability in NTFS-3G's ntfs_ie_lookup function. Attackers can exploit this by mounting a specially crafted...

Sep 7, 2021
CVE-2021-32975
7.8

CVE-2021-32975 is an out-of-bounds read vulnerability in Cscape software that could allow remote code execution when parsing malicious project files. ...

Aug 25, 2021
CVE-2021-31002
7.8

This vulnerability allows a malicious application to execute arbitrary code with system privileges on affected macOS systems. It's an out-of-bounds re...

Aug 24, 2021
CVE-2021-30991
7.8

This vulnerability allows a malicious application to execute arbitrary code with kernel privileges on iOS/iPadOS devices. An out-of-bounds read in the...

Aug 24, 2021
CVE-2021-30939
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing maliciously crafted images. It affects Apple devices r...

Aug 24, 2021
CVE-2021-28554
7.8

This vulnerability in Adobe Acrobat Reader DC allows an attacker to read memory outside intended boundaries, potentially leading to arbitrary code exe...

Aug 24, 2021
CVE-2021-28551
7.8

CVE-2021-28551 is an out-of-bounds read vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malicio...

Aug 24, 2021
CVE-2021-34315
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read in the BMP_loader.dll library when parsing malicious...

Jul 13, 2021
CVE-2021-31515
7.8

CVE-2021-31515 is an out-of-bounds read vulnerability in Vector 35 Binary Ninja's BNDB file parser that allows remote code execution. Attackers can ex...

Jun 29, 2021
CVE-2020-12980
7.8

This vulnerability in AMD Graphics Driver for Windows 10 allows attackers to write and read data outside intended memory boundaries. Successful exploi...

Jun 11, 2021
CVE-2021-22756
7.8

This vulnerability allows attackers to read memory beyond intended boundaries in Schneider Electric's IGSS Definition software when importing maliciou...

Jun 11, 2021
CVE-2020-12360
7.8

This vulnerability is an out-of-bounds read in Intel processor firmware that allows authenticated local users to potentially escalate privileges. It a...

Jun 9, 2021
CVE-2021-27490
7.8

This vulnerability allows an attacker to execute arbitrary code by exploiting an out-of-bounds read in KeyShot's 3D file reading modules. Attackers ca...

May 27, 2021
CVE-2021-31468
7.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a memory corruption flaw in Foxit Reader's U3D file handling. Attac...

May 7, 2021
CVE-2021-27027
7.8

An out-of-bounds read vulnerability in Autodesk FBX Review version 1.5.0 and earlier allows attackers to execute arbitrary code or disclose sensitive ...

Apr 19, 2021
CVE-2021-1753
7.8

CVE-2021-1753 is an out-of-bounds read vulnerability in Apple's image processing that could allow arbitrary code execution when processing a malicious...

Apr 2, 2021
CVE-2021-1790
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing malicious font files. It affects macOS systems running...

Apr 2, 2021
CVE-2021-1785
7.8

CVE-2021-1785 is an out-of-bounds read vulnerability in Apple's image processing that could allow arbitrary code execution when processing malicious i...

Apr 2, 2021
CVE-2021-1759
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing maliciously crafted images. It affects macOS, iOS, iPa...

Apr 2, 2021
CVE-2021-1757
7.8

CVE-2021-1757 is an out-of-bounds read vulnerability in Apple operating systems that allows a local attacker to potentially elevate their privileges. ...

Apr 2, 2021
CVE-2020-9960
7.8

CVE-2020-9960 is an out-of-bounds read vulnerability in Apple's audio file processing that could allow arbitrary code execution when processing malici...

Apr 2, 2021
CVE-2021-1736
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing maliciously crafted images. It affects macOS systems r...

Apr 2, 2021
CVE-2020-29618
7.8

CVE-2020-29618 is an out-of-bounds read vulnerability in Apple's image processing that could allow arbitrary code execution when processing malicious ...

Apr 2, 2021
CVE-2020-9147
7.8

CVE-2020-9147 is an out-of-bounds read vulnerability in Huawei smartphone component interfaces. Local attackers can exploit this by crafting malicious...

Apr 1, 2021
CVE-2021-27271
7.8

This vulnerability in Foxit PhantomPDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Mar 30, 2021
CVE-2021-27261
7.8

This vulnerability in Foxit PhantomPDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Mar 30, 2021
CVE-2021-27381
7.8

This vulnerability in Solid Edge CAD software allows attackers to execute arbitrary code by exploiting improper validation of PAR files. Users of Soli...

Mar 15, 2021
CVE-2021-21056
7.8

CVE-2021-21056 is an out-of-bounds read vulnerability in Adobe Framemaker that allows arbitrary code execution when a user opens a malicious file. Att...

Mar 12, 2021
CVE-2021-22638
7.8

CVE-2021-22638 is an out-of-bounds read vulnerability in Fatek FvDesigner software that allows arbitrary code execution when processing malicious proj...

Mar 3, 2021
CVE-2021-21050
7.8

CVE-2021-21050 is an out-of-bounds read vulnerability in Adobe Photoshop that allows arbitrary code execution when a user opens a malicious file. Atta...

Feb 11, 2021
CVE-2021-22663
7.8

CVE-2021-22663 is an out-of-bounds read vulnerability in Cscape software that allows arbitrary code execution when parsing malicious project files. At...

Feb 9, 2021
CVE-2020-26999
7.8

This vulnerability in Siemens JT2Go and Teamcenter Visualization allows attackers to leak sensitive information by exploiting improper validation of P...

Feb 9, 2021
CVE-2020-8672
7.8

This vulnerability is an out-of-bounds read in BIOS firmware affecting specific Intel processors. It allows an unauthenticated attacker with local acc...

Feb 2, 2021
CVE-2020-16236
7.8

CVE-2020-16236 is an out-of-bounds read vulnerability in FPWIN Pro that allows remote code execution when a user opens a malicious project file. This ...

Jan 26, 2021
CVE-2021-1068
7.8

This vulnerability in NVIDIA SHIELD TV's NVDEC component allows attackers to read from or write to memory outside intended buffer boundaries. It affec...

Jan 20, 2021
CVE-2020-27909
7.8

CVE-2020-27909 is an out-of-bounds read vulnerability in Apple's audio file processing that could allow arbitrary code execution when processing a mal...

Dec 8, 2020
CVE-2020-9965
7.8

CVE-2020-9965 is an out-of-bounds read vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privi...

Dec 8, 2020
CVE-2020-5991
7.8

This vulnerability in NVIDIA's NVJPEG library allows attackers to perform out-of-bounds read/write operations, potentially leading to code execution, ...

Oct 30, 2020
CVE-2020-9973
7.8

This vulnerability allows attackers to cause out-of-bounds memory reads when processing malicious USD (Universal Scene Description) files. Successful ...

Oct 27, 2020
CVE-2020-9984
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing maliciously crafted images. It affects Apple iOS, iPad...

Oct 22, 2020
CVE-2020-9873
7.8

This vulnerability allows arbitrary code execution when processing maliciously crafted images due to an out-of-bounds read. It affects multiple Apple ...

Oct 22, 2020
CVE-2020-9877
7.8

CVE-2020-9877 is an out-of-bounds read vulnerability in Apple's image processing that could allow arbitrary code execution when processing malicious i...

Oct 22, 2020
CVE-2020-24418
7.8

CVE-2020-24418 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to execute arbitrary code in the context of ...

Oct 21, 2020
CVE-2020-9749
7.8

CVE-2020-9749 is an out-of-bounds read vulnerability in Adobe Animate that could allow arbitrary code execution when a user opens a malicious .fla fil...

Oct 21, 2020
CVE-2020-24409
7.8

CVE-2020-24409 is an out-of-bounds read vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious PDF...

Oct 20, 2020

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,835 CVEs classified as CWE-125, with 193 rated critical and 1,094 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free