CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,856)
This vulnerability in NVIDIA's NVJPEG library allows attackers to perform out-of-bounds read/write operations, potentially leading to code execution, ...
Oct 30, 2020This vulnerability allows attackers to cause out-of-bounds memory reads when processing malicious USD (Universal Scene Description) files. Successful ...
Oct 27, 2020This vulnerability allows attackers to execute arbitrary code by tricking users into processing maliciously crafted images. It affects Apple iOS, iPad...
Oct 22, 2020This vulnerability allows arbitrary code execution when processing maliciously crafted images due to an out-of-bounds read. It affects multiple Apple ...
Oct 22, 2020CVE-2020-9877 is an out-of-bounds read vulnerability in Apple's image processing that could allow arbitrary code execution when processing malicious i...
Oct 22, 2020CVE-2020-24418 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to execute arbitrary code in the context of ...
Oct 21, 2020CVE-2020-9749 is an out-of-bounds read vulnerability in Adobe Animate that could allow arbitrary code execution when a user opens a malicious .fla fil...
Oct 21, 2020CVE-2020-24409 is an out-of-bounds read vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious PDF...
Oct 20, 2020This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious audio files. It affects Apple devices running o...
Oct 16, 2020This vulnerability allows attackers to execute arbitrary code by tricking users into processing a malicious audio file. It affects Apple iOS, iPadOS, ...
Oct 16, 2020CVE-2020-9799 is an out-of-bounds read vulnerability in macOS that allows malicious applications to execute arbitrary code with kernel privileges. Thi...
Oct 16, 2020CVE-2020-25188 is an out-of-bounds read vulnerability in LAquis SCADA software that allows remote code execution. An attacker can exploit this by tric...
Oct 14, 2020This vulnerability in Foxit Studio Photo allows remote attackers to execute arbitrary code by tricking users into opening malicious TIF files. The fla...
Aug 20, 2020This vulnerability is an out-of-bounds read in certain Intel Graphics Drivers that could allow an authenticated local user to potentially escalate pri...
Aug 13, 2020Adobe Premiere Pro versions 14.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to execute arbitrary code. This af...
Jun 25, 2020CVE-2020-9815 is an out-of-bounds read vulnerability in Apple's audio file processing that could allow arbitrary code execution when processing a mali...
Jun 9, 2020CVE-2020-9791 is an out-of-bounds read vulnerability in Apple's audio file processing that could allow arbitrary code execution when processing malici...
Jun 9, 2020This vulnerability allows remote attackers to execute arbitrary code on Foxit PhantomPDF installations by tricking users into opening malicious PDF fi...
Apr 22, 2020This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U...
Apr 22, 2020This vulnerability in the Linux kernel's BPF verifier allows attackers to bypass memory bounds checks for 32-bit operations, leading to out-of-bounds ...
Apr 2, 2020This CVE describes an out-of-bounds read vulnerability in macOS kernel memory that could allow an attacker to cause system crashes or read sensitive k...
Feb 11, 2026A kernel memory corruption vulnerability in Linux ipvlan driver allows local attackers to trigger out-of-bounds memory access, potentially leading to ...
Apr 28, 2024This CVE describes a shift-out-of-bounds vulnerability in the Linux kernel's scheduler load_balance() function. It could allow local attackers to caus...
Feb 28, 2024An integer overflow vulnerability in Silicon Labs Gecko Bootloader versions 4.3.1 and earlier allows attackers to access memory beyond allocated bound...
Oct 20, 2023CVE-2026-27831 is a heap-based out-of-bounds read vulnerability in rldns DNS server version 2.3 that can cause denial of service. The vulnerability al...
Feb 26, 2026This vulnerability in FreeRDP allows a malicious RDP server to trigger an out-of-bounds read by sending an execResult value of 7 or greater. This coul...
Feb 25, 2026ImageMagick versions before 7.1.2-15 and 6.9.13-40 have a heap information disclosure vulnerability in their PSD format handler. When processing speci...
Feb 24, 2026This vulnerability in Valkey allows attackers with access to the clusterbus port to send specially crafted packets that cause out-of-bounds reads, pot...
Feb 23, 2026A remote array index out-of-bounds vulnerability in free5GC's AMF component allows attackers to crash the AMF service via specially crafted 5GS Mobile...
Feb 13, 2026CVE-2025-69806 is an out-of-bounds read vulnerability in p2r3 bareiron software that allows unauthenticated remote attackers to leak relative informat...
Feb 12, 2026Fast DDS versions prior to 3.4.1, 3.3.1, and 2.6.11 contain a vulnerability where malicious ParticipantGenericMessage packets can trigger excessive me...
Feb 3, 2026This vulnerability in Fast DDS allows remote attackers to cause a denial-of-service (DoS) by sending specially crafted SPDP packets with modified DATA...
Feb 3, 2026This vulnerability in Fast DDS allows remote attackers to cause a denial of service by triggering an out-of-memory condition. When security mode is en...
Feb 3, 2026An out-of-bounds read vulnerability in Monkey web server's HTTP parser allows attackers to cause denial of service by sending crafted HTTP requests. T...
Jan 29, 2026An out-of-bounds read vulnerability in Monkey web server's mk_mimetype_find function allows attackers to cause denial of service by sending specially ...
Jan 29, 2026This vulnerability allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the Monkey web server. The out-o...
Jan 29, 2026An out-of-bounds read vulnerability in Monkey web server's memory handling allows attackers to cause denial of service by sending crafted HTTP request...
Jan 29, 2026An out-of-bounds read vulnerability in Monkey web server's mk_vhost_fdt_close function allows attackers to cause denial of service by sending crafted ...
Jan 29, 2026An out-of-bounds read vulnerability in GPAC's GSF demuxer filter allows attackers to cause denial of service by processing a malicious .gsf file. This...
Jan 15, 2026This CVE describes an information disclosure vulnerability in PHP's getimagesize() function where uninitialized heap memory can leak into image metada...
Dec 27, 2025A denial-of-service vulnerability in the omec-project UPF's pfcpiface component allows attackers to crash the UPF process by sending specially crafted...
Dec 18, 2025A denial-of-service vulnerability in the omec-project UPF's pfcpiface component allows attackers to crash the UPF by sending specially crafted PFCP Se...
Dec 18, 2025ImageMagick's TIM image parser contains an integer overflow vulnerability that allows attackers to trigger out-of-bounds memory reads by providing spe...
Dec 10, 2025This vulnerability allows remote attackers to read sensitive information from memory without authentication or user interaction. It affects Android de...
Dec 8, 2025This vulnerability in the BACnet Protocol Stack library allows out-of-bounds memory reads when processing specially crafted BACnet network protocol da...
Dec 5, 2025An out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows attackers to read memory beyond intended boundaries by providing a large ...
Dec 2, 2025This vulnerability in WebKitGTK and WPE WebKit allows remote attackers to cause a denial-of-service (DoS) by crashing the UIProcess through a crafted ...
Nov 25, 2025This vulnerability in ThinkPHP 5.0.24 allows attackers to read arbitrary files on the server through crafted template values. It affects any applicati...
Nov 20, 2025This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's media component by tricking users into visiting a m...
Nov 6, 2025This vulnerability involves boundary checking bugs in Xen's handling of Viridian hypercalls, allowing out-of-bounds reads and writes. Attackers could ...
Oct 31, 2025About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,856 CVEs classified as CWE-125, with 198 rated critical and 1,110 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free