CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,859
Total CVEs
198
Critical
1,113
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,859)

CVE-2025-58147
7.5

This vulnerability involves boundary checking bugs in Xen's handling of Viridian hypercalls, allowing out-of-bounds reads and writes. Attackers could ...

Oct 31, 2025
CVE-2025-55085
7.5

This vulnerability in NextX Duo's HTTP client module allows a malicious server response to trigger undefined behavior through improper bounds checking...

Oct 17, 2025
CVE-2025-55094
7.5

This vulnerability in NetX Duo's ICMPv6 packet processing allows attackers to read memory beyond intended boundaries when handling specially crafted I...

Oct 17, 2025
CVE-2025-55087
7.5

This vulnerability in NextX Duo's SNMP addon allows attackers to trigger an out-of-bounds read via specially crafted SNMPv3 security parameters. This ...

Oct 17, 2025
CVE-2025-61951
7.5

This vulnerability allows attackers to cause denial of service by sending undisclosed traffic to F5 BIG-IP systems with specific DTLS configurations. ...

Oct 15, 2025
CVE-2025-54854
7.5

This vulnerability allows attackers to cause denial of service by sending specific traffic to BIG-IP APM systems with OAuth access profiles configured...

Oct 15, 2025
CVE-2025-9230
7.5

This OpenSSL vulnerability allows attackers to trigger out-of-bounds memory operations when applications decrypt CMS messages using password-based enc...

Sep 30, 2025
CVE-2025-11021
7.5

This vulnerability in libsoup's cookie date handling allows out-of-bounds memory reads when processing maliciously crafted cookie expiration dates. It...

Sep 26, 2025
CVE-2025-53805
7.5

This vulnerability allows an unauthorized attacker to trigger an out-of-bounds read in Windows Internet Information Services (IIS) through network acc...

Sep 9, 2025
CVE-2025-40797
7.5

An out-of-bounds read vulnerability in the User Management Component (UMC) of SIMATIC PCS neo industrial control systems allows unauthenticated remote...

Sep 9, 2025
CVE-2023-43692
7.5

This vulnerability involves out-of-bounds reads in Malwarebytes string detection utilities that can cause system crashes. It affects Malwarebytes cons...

Aug 14, 2025
CVE-2024-42646
7.5

A segmentation fault vulnerability in NanoMQ v0.21.10 allows attackers to cause Denial of Service (DoS) by sending specially crafted messages. This af...

Jul 14, 2025
CVE-2025-5777
KEV EPSS 77.6% 7.5

CVE-2025-5777 (CitrixBleed 2) is a memory disclosure vulnerability in Citrix NetScaler ADC and Gateway appliances. Insufficient input validation allow...

Jun 17, 2025
CVE-2025-29971
7.5

An out-of-bounds read vulnerability in Microsoft Web Threat Defense (WTD.sys) allows unauthorized attackers to cause denial of service over a network....

May 13, 2025
CVE-2025-30176
7.5

An out-of-bounds read buffer overflow vulnerability in Siemens' User Management Component (UMC) affects multiple industrial automation products. This ...

May 13, 2025
CVE-2025-30174
7.5

An out-of-bounds read buffer overflow vulnerability in Siemens industrial automation products allows unauthenticated remote attackers to cause denial ...

May 13, 2025
CVE-2025-32906
7.5

An out-of-bounds read vulnerability in libsoup's soup_headers_parse_request() function allows attackers to crash HTTP servers via specially crafted HT...

Apr 14, 2025
CVE-2024-12055
7.5

A vulnerability in Ollama versions up to 0.3.14 allows attackers to upload specially crafted gguf model files that cause an out-of-bounds read, crashi...

Mar 20, 2025
CVE-2024-50600
7.5

This vulnerability allows attackers to send malformed messages through the Wi-Fi driver to Samsung Exynos processors, causing out-of-bounds memory acc...

Mar 6, 2025
CVE-2025-24497
7.5

This vulnerability in F5 BIG-IP systems allows attackers to cause Traffic Management Microkernel (TMM) termination by sending specific requests to vir...

Feb 5, 2025
CVE-2025-0612
7.5

This vulnerability allows remote attackers to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to heap corrup...

Jan 22, 2025
CVE-2024-24417
7.5

A buffer overflow vulnerability in Magma's decode_protocol_configuration_options function allows attackers to cause Denial of Service (DoS) via crafte...

Jan 21, 2025
CVE-2024-46670
7.5

An out-of-bounds read vulnerability in FortiOS IPsec IKE service allows unauthenticated remote attackers to trigger memory consumption leading to deni...

Jan 14, 2025
CVE-2025-21598
7.5

An out-of-bounds read vulnerability in Juniper Junos OS and Junos OS Evolved routing protocol daemon (rpd) allows unauthenticated attackers to crash t...

Jan 9, 2025
CVE-2024-48456
EPSS 76.4% 7.5

This vulnerability allows a remote attacker to obtain sensitive information, specifically the admin password, via the password parameter on the change...

Jan 6, 2025
CVE-2024-48457
EPSS 52.4% 7.5

This vulnerability in multiple Netis router models allows remote attackers to access sensitive information through specific endpoints and binaries. Af...

Jan 6, 2025
CVE-2024-53834
7.5

This vulnerability in Android's SMS utilities allows remote attackers to read memory beyond intended boundaries without user interaction, potentially ...

Jan 3, 2025
CVE-2024-47778
7.5

This CVE describes an out-of-bounds read vulnerability in GStreamer's WAV file parser that occurs when processing malformed ADTL chunks. Attackers can...

Dec 12, 2024
CVE-2024-47596
7.5

This vulnerability in GStreamer's QuickTime demuxer allows an out-of-bounds read when processing specially crafted media files. Attackers could exploi...

Dec 12, 2024
CVE-2024-47602
7.5

A null pointer dereference vulnerability in GStreamer's matroska demuxer can cause application crashes when processing specially crafted media files. ...

Dec 12, 2024
CVE-2024-47543
7.5

This CVE describes an out-of-bounds read vulnerability in GStreamer's qtdemux component that occurs when parsing malformed media containers. Attackers...

Dec 12, 2024
CVE-2024-37401
7.5

An out-of-bounds read vulnerability in the IPsec implementation of Ivanti Connect Secure allows remote unauthenticated attackers to cause denial of se...

Dec 12, 2024
CVE-2024-53450
7.5

RAGFlow 0.13.0 has an improper access control vulnerability in document-hooks.ts that allows unauthenticated attackers to access user documents. This ...

Dec 9, 2024
CVE-2024-20138
7.5

This vulnerability in MediaTek wlan drivers allows remote attackers to read memory beyond intended boundaries without authentication or user interacti...

Dec 2, 2024
CVE-2024-20129
7.5

This CVE describes an out-of-bounds read vulnerability in MediaTek telephony components that could allow remote denial of service attacks. The vulnera...

Dec 2, 2024
CVE-2024-20127
7.5

This CVE describes an out-of-bounds read vulnerability in Telephony components that could allow remote attackers to cause denial of service without us...

Dec 2, 2024
CVE-2024-20128
7.5

This CVE describes an out-of-bounds read vulnerability in MediaTek telephony components that could allow remote denial of service attacks without user...

Dec 2, 2024
CVE-2024-45520
7.5

CVE-2024-45520 is a memory corruption vulnerability in WithSecure Atlant (formerly F-Secure Atlant) that allows remote attackers to cause denial of se...

Dec 1, 2024
CVE-2024-36612
7.5

Zulip versions 8.0 through 8.3 contain a memory leak vulnerability in popover handling that allows attackers to gradually exhaust server memory throug...

Nov 29, 2024
CVE-2024-51569
7.5

This CVE describes an out-of-bounds read vulnerability in Apache NimBLE's Bluetooth stack. It allows reading beyond allocated memory boundaries when p...

Nov 26, 2024
CVE-2024-36254
7.5

An out-of-bounds read vulnerability in Sharp and Toshiba Tec multifunction printers could allow attackers to cause denial-of-service conditions by sen...

Nov 26, 2024
CVE-2018-9484
7.5

CVE-2018-9484 is an out-of-bounds read vulnerability in Android's Bluetooth stack that allows remote attackers to read memory contents without authent...

Nov 20, 2024
CVE-2018-9456
7.5

CVE-2018-9456 is an out-of-bounds read vulnerability in Android's Bluetooth SDP (Service Discovery Protocol) implementation that could allow remote at...

Nov 19, 2024
CVE-2023-39179
7.5

CVE-2023-39179 is an out-of-bounds read vulnerability in the Linux kernel's ksmbd SMB2 module that allows attackers to read sensitive kernel memory. T...

Nov 18, 2024
CVE-2024-38649
7.5

This vulnerability allows remote unauthenticated attackers to trigger an out-of-bounds write in the IPsec component of Ivanti Connect Secure, potentia...

Nov 13, 2024
CVE-2024-42420
7.5

Sharp and Toshiba Tec multifunction printers (MFPs) contain out-of-bounds read vulnerabilities in their web interfaces. Attackers can crash affected d...

Oct 25, 2024
CVE-2024-43562
7.5

This vulnerability in Windows Network Address Translation (NAT) allows attackers to cause a denial of service condition by sending specially crafted n...

Oct 8, 2024
CVE-2024-44912
7.5

NASA CryptoLib v1.3.0 contains an out-of-bounds read vulnerability in the TM subsystem (crypto_tm.c) that could allow attackers to read sensitive memo...

Sep 27, 2024
CVE-2024-44910
7.5

CVE-2024-44910 is an out-of-bounds read vulnerability in NASA CryptoLib v1.3.0's AOS subsystem that could allow attackers to read sensitive memory con...

Sep 27, 2024
CVE-2024-36980
7.5

An out-of-bounds read vulnerability in OpenPLC Runtime's EtherNet/IP PCCC parser allows attackers to cause denial of service via specially crafted net...

Sep 18, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,859 CVEs classified as CWE-125, with 198 rated critical and 1,113 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free