CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,859
Total CVEs
198
Critical
1,113
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,859)

CVE-2024-44460
7.5

CVE-2024-44460 is an out-of-bounds read vulnerability in Nanomq v0.21.9 that allows attackers to trigger a Denial of Service (DoS) by causing the MQTT...

Sep 12, 2024
CVE-2024-5991
7.5

CVE-2024-5991 is an out-of-bounds read vulnerability in wolfSSL's X509 certificate hostname validation. Attackers can cause the library to read beyond...

Aug 27, 2024
CVE-2024-38148
7.5

This vulnerability in Windows Secure Channel allows attackers to cause a denial of service by sending specially crafted packets to vulnerable systems....

Aug 13, 2024
CVE-2024-38132
7.5

This vulnerability in Windows Network Address Translation (NAT) allows attackers to cause a denial of service condition by sending specially crafted n...

Aug 13, 2024
CVE-2024-31714
7.5

A buffer overflow vulnerability in Waxlab wax versions 0.9-3 and earlier allows attackers to cause denial of service through the Lua library component...

May 20, 2024
CVE-2024-34950
7.5

This CVE describes a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module of D-Link DIR-822+ routers. Attackers can ex...

May 14, 2024
CVE-2024-33781
7.5

CVE-2024-33781 is a stack buffer overflow vulnerability in MP-SPDZ v0.3.8's octetStream::get_bytes function that allows attackers to cause denial of s...

May 7, 2024
CVE-2024-34251
7.5

An out-of-bounds memory read vulnerability in Bytecode Alliance wasm-micro-runtime v2.0.0 allows remote attackers to cause denial of service by exploi...

May 6, 2024
CVE-2024-34246
7.5

CVE-2024-34246 is an out-of-bounds memory read vulnerability in wasm3 v0.5.0 that can cause segmentation faults and potential denial of service. This ...

May 6, 2024
CVE-2024-33763
7.5

CVE-2024-33763 is a stack-buffer-underflow vulnerability in lunasvg's layoutcontext.cpp that allows reading memory before the start of a buffer. This ...

May 1, 2024
CVE-2024-23528
7.5

An out-of-bounds read vulnerability in Ivanti Avalanche's WLAvalancheService component allows unauthenticated remote attackers to read sensitive infor...

Apr 19, 2024
CVE-2024-23530
7.5

An unauthenticated remote attacker can exploit an out-of-bounds read vulnerability in Ivanti Avalanche's WLAvalancheService component to read sensitiv...

Apr 19, 2024
CVE-2024-23532
7.5

An authenticated remote attacker can exploit an out-of-bounds read vulnerability in the WLAvalancheService component of Ivanti Avalanche to cause deni...

Apr 19, 2024
CVE-2023-51391
7.5

A vulnerability in Micrium OS Network HTTP Server allows invalid pointer dereference during HTTP header processing, potentially causing device crashes...

Apr 16, 2024
CVE-2024-30604
7.5

Tenda FH1203 router firmware version 2.0.1.6 contains a stack overflow vulnerability in the fromDhcpListClient function's list1 parameter. This allows...

Mar 28, 2024
CVE-2024-26003
7.5

CVE-2024-26003 is an out-of-bounds read vulnerability in a charging system control agent that allows unauthenticated remote attackers to cause a denia...

Mar 12, 2024
CVE-2024-27206
7.5

CVE-2024-27206 is an out-of-bounds read vulnerability in Android Pixel devices that allows remote attackers to read memory beyond intended boundaries ...

Mar 11, 2024
CVE-2024-22011
7.5

This vulnerability allows remote attackers to read memory outside intended bounds in Android's ss_ProcessRejectComponent function, potentially exposin...

Mar 11, 2024
CVE-2024-1546
7.5

This vulnerability allows attackers to read memory outside the intended buffer boundaries when Firefox, Firefox ESR, or Thunderbird processes network ...

Feb 20, 2024
CVE-2024-20687
7.5

This vulnerability in Microsoft's AllJoyn API allows attackers to cause a denial of service by sending specially crafted packets. It affects systems r...

Jan 9, 2024
CVE-2023-49552
7.5

CVE-2023-49552 is an out-of-bounds write vulnerability in Cesanta mjs 2.20.0's mjs_op_json_stringify function that allows remote attackers to cause de...

Jan 2, 2024
CVE-2023-52152
7.5

CVE-2023-52152 is an out-of-bounds read vulnerability in mUPnP for C's URI parsing component that can cause application crashes. This affects any appl...

Dec 28, 2023
CVE-2023-51713
7.5

CVE-2023-51713 is a one-byte out-of-bounds read vulnerability in ProFTPD's make_ftp_cmd function that can cause the FTP daemon to crash. This affects ...

Dec 22, 2023
CVE-2023-48404
7.5

This vulnerability allows remote attackers to read memory outside intended bounds in Android's ProtocolMiscCarrierConfigSimInfoIndAdapter component, p...

Dec 8, 2023
CVE-2023-48398
7.5

This CVE describes an out-of-bounds read vulnerability in the baseband firmware of certain Android devices. Attackers could potentially read sensitive...

Dec 8, 2023
CVE-2023-46767
7.5

This CVE describes an out-of-bounds write vulnerability in a kernel driver module that could allow attackers to cause process exceptions or potentiall...

Nov 8, 2023
CVE-2023-46762
7.5

CVE-2023-46762 is an out-of-bounds write vulnerability in a kernel driver module that could allow attackers to write data beyond allocated memory boun...

Nov 8, 2023
CVE-2023-5998
7.5

CVE-2023-5998 is an out-of-bounds read vulnerability in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. Th...

Nov 7, 2023
CVE-2023-21347
7.5

This Bluetooth vulnerability allows attackers to read memory beyond intended boundaries without user interaction, potentially exposing sensitive infor...

Oct 30, 2023
CVE-2023-21353
7.5

CVE-2023-21353 is an out-of-bounds read vulnerability in Android's NFC stack (NFA) that allows remote attackers to read memory contents without authen...

Oct 30, 2023
CVE-2023-31122
7.5

An out-of-bounds read vulnerability in the mod_macro module of Apache HTTP Server allows attackers to read memory beyond allocated buffers. This affec...

Oct 23, 2023
CVE-2023-35663
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's protocolnetadapter component, potentially exposing s...

Oct 18, 2023
CVE-2023-23581
7.5

A denial-of-service vulnerability in SoftEther VPN's vpnserver component allows attackers to crash the VPN service by sending specially crafted networ...

Oct 12, 2023
CVE-2023-35652
7.5

This CVE describes an out-of-bounds read vulnerability in Android's baseband firmware that could allow remote information disclosure. Attackers could ...

Oct 11, 2023
CVE-2023-35661
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's ROHC packet decompression code. It affects Android d...

Oct 11, 2023
CVE-2023-34359
7.5

This vulnerability allows remote unauthenticated attackers to cause a denial-of-service condition on ASUS RT-AX88U routers by sending a specially craf...

Jul 31, 2023
CVE-2023-35694
7.5

This vulnerability allows remote attackers to read memory outside intended bounds in Android's DMPixelLogger component, potentially exposing sensitive...

Jul 13, 2023
CVE-2023-32044
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows an unauthenticated attacker to send specially crafted packets to cause a denial of servi...

Jul 11, 2023
CVE-2023-21223
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's LPP (LTE Positioning Protocol) component, potentiall...

Jun 28, 2023
CVE-2023-21197
7.5

This vulnerability allows remote attackers to read memory beyond intended bounds in Android's Bluetooth stack, potentially disclosing sensitive inform...

Jun 28, 2023
CVE-2023-21201
7.5

This vulnerability in Android's Bluetooth stack allows remote attackers to cause denial of service via an out-of-bounds read. Attackers can exploit th...

Jun 28, 2023
CVE-2023-30362
7.5

This CVE describes a buffer overflow vulnerability in the coap_send function of libcoap library versions up to 4.3.1-103-g52cfd56. Attackers can explo...

Jun 23, 2023
CVE-2023-24535
7.5

This vulnerability in the Go protobuf library causes a panic when parsing malformed text-format messages containing a minus sign followed by whitespac...

Jun 8, 2023
CVE-2021-46794
7.5

This vulnerability in AMD Secure Processor firmware allows attackers to trigger a data abort through insufficient bounds checking in SMI mailbox check...

May 9, 2023
CVE-2021-31239
7.5

CVE-2021-31239 is an out-of-bounds read vulnerability in SQLite's appendvfs.c that allows remote attackers to cause denial of service through applicat...

May 9, 2023
CVE-2023-21769
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows an unauthenticated attacker to send specially crafted packets to an MSMQ server, causing...

Apr 11, 2023
CVE-2023-27728
7.5

This vulnerability in Nginx NJS v0.7.10 allows attackers to trigger a segmentation violation via the njs_dump_is_recursive function, potentially causi...

Apr 9, 2023
CVE-2023-27730
7.5

CVE-2023-27730 is a memory corruption vulnerability in Nginx NJS JavaScript engine that can cause segmentation faults via the njs_lvlhsh_find function...

Apr 9, 2023
CVE-2023-22845
7.5

An out-of-bounds read vulnerability in OpenImageIO's TGA file parser allows attackers to read memory beyond allocated buffers via specially crafted Ta...

Mar 30, 2023
CVE-2023-25659
7.5

This vulnerability in TensorFlow allows an out-of-bounds read when the DynamicStitch operation receives mismatched indices and data shapes, potentiall...

Mar 25, 2023

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,859 CVEs classified as CWE-125, with 198 rated critical and 1,113 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free