CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,859
Total CVEs
198
Critical
1,113
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,859)

CVE-2023-21053
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's cell broadcast message processing. It could disclose...

Mar 24, 2023
CVE-2023-21059
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's LPP_LcsManagement component, potentially disclosing ...

Mar 24, 2023
CVE-2023-27857
7.5

This vulnerability in Rockwell Automation's ThinManager ThinServer allows unauthenticated remote attackers to trigger a heap-based buffer over-read by...

Mar 22, 2023
CVE-2022-35729
7.5

An out-of-bounds read vulnerability in OpenBMC firmware for certain Intel platforms allows unauthenticated attackers to potentially cause denial of se...

Feb 16, 2023
CVE-2023-21691
7.5

This vulnerability in Microsoft's Protected Extensible Authentication Protocol (PEAP) allows an attacker to disclose sensitive information from memory...

Feb 14, 2023
CVE-2023-25567
7.5

CVE-2023-25567 is an out-of-bounds read vulnerability in GSS-NTLMSSP, a plugin for GSSAPI that handles NTLM authentication. Attackers can trigger this...

Feb 14, 2023
CVE-2023-24977
7.5

This CVE describes an out-of-bounds read vulnerability in Apache InLong that could allow attackers to read sensitive information from memory. It affec...

Feb 1, 2023
CVE-2022-34037
7.5

CVE-2022-34037 is an out-of-bounds read vulnerability in Caddy web server's rewrite module that can cause denial of service. Attackers can crash the s...

Jul 22, 2022
CVE-2022-20224
7.5

This vulnerability in Android's Bluetooth stack allows remote attackers to read memory beyond intended boundaries without user interaction. It affects...

Jul 13, 2022
CVE-2022-34742
7.5

CVE-2022-34742 is an out-of-bounds read vulnerability in Huawei system modules that allows attackers to read sensitive memory data. This affects Huawe...

Jul 12, 2022
CVE-2021-33649
7.5

CVE-2021-33649 is an out-of-bounds read vulnerability in MindSpore's Transpose operator that occurs when the perm parameter exceeds input shape bounds...

Jun 27, 2022
CVE-2022-22065
7.5

This vulnerability is an out-of-bounds read in the WLAN HOST component of Qualcomm Snapdragon chipsets due to improper length checking. It affects mul...

Jun 14, 2022
CVE-2021-35086
7.5

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing NR system information messages. Attackers could po...

Jun 14, 2022
CVE-2021-35100
7.5

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing ID3 tags in media files. It allows attackers to read memory beyo...

Jun 14, 2022
CVE-2021-46814
7.5

CVE-2021-46814 is an out-of-bounds memory read/write vulnerability in Huawei's video framework that could allow attackers to crash systems or potentia...

Jun 13, 2022
CVE-2022-31001
7.5

CVE-2022-31001 is an out-of-bounds read vulnerability in Sofia-SIP library that can cause crashes when processing malicious SDP messages. Attackers ca...

May 31, 2022
CVE-2021-42870
7.5

CVE-2021-42870 is an out-of-bounds read vulnerability in ACCEL-PPP 1.12.0 that occurs when processing call_clear_request messages. This allows attacke...

May 16, 2022
CVE-2022-28739
7.5

This vulnerability is a buffer over-read in Ruby's String-to-Float conversion functions (Kernel#Float and String#to_f). It allows attackers to read me...

May 9, 2022
CVE-2022-27406
7.5

CVE-2022-27406 is a memory corruption vulnerability in FreeType's FT_Request_Size function that can cause segmentation faults or potentially allow arb...

Apr 22, 2022
CVE-2021-39809
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's Bluetooth AVRCP (Audio/Video Remote Control Profile)...

Apr 12, 2022
CVE-2022-26380
7.5

This vulnerability affects Siemens SCALANCE industrial network switches. It allows attackers to trigger device reboots by sending specially crafted SN...

Apr 12, 2022
CVE-2021-3422
7.5

A lack of validation in the Splunk-to-Splunk protocol allows attackers to cause denial-of-service in vulnerable Splunk Enterprise instances. This affe...

Mar 25, 2022
CVE-2021-39726
7.5

This CVE describes an out-of-bounds read vulnerability in the Android kernel's cd_ParseMsg function. It allows remote attackers to read memory beyond ...

Mar 16, 2022
CVE-2021-3610
7.5

This heap-based buffer overflow vulnerability in ImageMagick's TIFF image processing allows attackers to crash applications or potentially execute arb...

Feb 24, 2022
CVE-2021-39677
7.5

This vulnerability allows attackers to read memory outside the allocated buffer when the camera buffer size is zero, potentially exposing sensitive in...

Feb 11, 2022
CVE-2022-24314
7.5

CVE-2022-24314 is an out-of-bounds read vulnerability in Schneider Electric's Interactive Graphical SCADA System Data Server that could cause memory l...

Feb 9, 2022
CVE-2021-41040
7.5

CVE-2021-41040 is an out-of-bounds read vulnerability in Eclipse Wakaama's CoAP parsing code that allows attackers to read sensitive memory contents. ...

Feb 1, 2022
CVE-2020-19861
7.5

CVE-2020-19861 is a heap-based buffer overflow vulnerability in ldns 1.7.1's zone file parsing function. When processing malicious DNS zone files, the...

Jan 21, 2022
CVE-2022-21688
7.5

CVE-2022-21688 is a denial-of-service vulnerability in OnionShare desktop application where specially crafted images cause excessive memory consumptio...

Jan 18, 2022
CVE-2021-39984
7.5

This vulnerability in Huawei's idap module allows attackers to read memory outside intended boundaries, potentially causing denial of service. It affe...

Jan 3, 2022
CVE-2021-1002
7.5

This CVE describes an out-of-bounds read vulnerability in Android's WT_Interpolate function that could allow remote attackers to read sensitive memory...

Dec 15, 2021
CVE-2021-0925
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's NFC Type 4 Tag processing code. It could lead to inf...

Dec 15, 2021
CVE-2021-37076
7.5

This CVE describes an out-of-bounds read vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation could allow an attacker to cau...

Dec 7, 2021
CVE-2021-37066
7.5

CVE-2021-37066 is an out-of-bounds read vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation can cause process crashes, pote...

Dec 7, 2021
CVE-2021-34424
7.5

This vulnerability in Zoom clients and servers allows attackers to read arbitrary memory contents, potentially exposing sensitive information like ses...

Nov 24, 2021
CVE-2021-37015
7.5

This is an out-of-bounds read vulnerability in Huawei smartphone kernels that allows attackers to read memory beyond allocated buffers. Successful exp...

Nov 23, 2021
CVE-2021-1981
7.5

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets due to improper size checking of Bearer capability information elements in MT...

Nov 12, 2021
CVE-2021-1977
7.5

This vulnerability allows attackers to read beyond allocated memory boundaries during AEAD decryption in Qualcomm Snapdragon chipsets. It affects devi...

Oct 20, 2021
CVE-2021-42054
7.5

ACCEL-PPP 1.12.0 contains an out-of-bounds read vulnerability in the triton_context_schedule function that occurs when a client disconnects after auth...

Oct 7, 2021
CVE-2021-36160
7.5

CVE-2021-36160 is an out-of-bounds read vulnerability in Apache HTTP Server's mod_proxy_uwsgi module. A specially crafted URI path can cause the serve...

Sep 16, 2021
CVE-2021-30660
7.5

This vulnerability allows a malicious application to read kernel memory beyond intended boundaries, potentially exposing sensitive system information....

Sep 8, 2021
CVE-2021-40516
7.5

CVE-2021-40516 is an out-of-bounds read vulnerability in WeeChat's Relay plugin that allows remote attackers to crash the application via specially cr...

Sep 5, 2021
CVE-2021-23437
7.5

This vulnerability in Pillow (Python Imaging Library) allows attackers to cause Denial of Service (DoS) through a Regular Expression Denial of Service...

Sep 3, 2021
CVE-2020-36426
7.5

This vulnerability in Arm Mbed TLS allows attackers to read one byte beyond the allocated buffer when parsing Certificate Revocation Lists (CRLs) in D...

Jul 19, 2021
CVE-2021-0596
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries via NFC communication, potentially disclosing sensitive informati...

Jul 14, 2021
CVE-2021-1943
7.5

This vulnerability allows attackers to read memory beyond allocated buffer boundaries in Qualcomm Snapdragon chipsets when parsing beacon responses. I...

Jul 13, 2021
CVE-2021-0522
7.5

This vulnerability in Android's Bluetooth stack allows remote attackers to read memory they shouldn't access via a use-after-free bug in SDP callback ...

Jun 21, 2021
CVE-2021-27408
7.5

This vulnerability allows attackers to read memory beyond intended boundaries in Welch Allyn medical device management tools, potentially leaking sens...

Jun 11, 2021
CVE-2021-27597
7.5

CVE-2021-27597 is a denial-of-service vulnerability in SAP NetWeaver AS for ABAP RFC Gateway caused by improper input validation in the memmove() meth...

Jun 9, 2021
CVE-2020-11241
7.5

This vulnerability allows an attacker to trigger an out-of-bounds read in Qualcomm Snapdragon chipsets when processing EAPOL keys with insufficient le...

Jun 9, 2021

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,859 CVEs classified as CWE-125, with 198 rated critical and 1,113 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free