CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,859
Total CVEs
198
Critical
1,113
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,859)

CVE-2020-27840
7.5

This vulnerability in Samba allows attackers to cause a denial-of-service by sending specially crafted domain name strings with spaces. When Samba pro...

May 12, 2021
CVE-2021-20277
7.5

This vulnerability in Samba's libldb allows an attacker to crash the LDAP server process by sending LDAP requests with multiple consecutive leading sp...

May 12, 2021
CVE-2021-0261
7.5

An unauthenticated attacker can cause a denial of service (DoS) in Juniper Junos OS by sending a high volume of specific HTTP/HTTPS requests to servic...

Apr 22, 2021
CVE-2021-30139
7.5

This vulnerability in Alpine Linux's apk-tools package manager allows a buffer overflow when parsing malicious tarball files, potentially leading to a...

Apr 21, 2021
CVE-2020-36281
7.5

CVE-2020-36281 is a heap-based buffer over-read vulnerability in Leptonica's color quantization function. This allows attackers to read memory beyond ...

Mar 12, 2021
CVE-2020-36279
7.5

This CVE describes a heap-based buffer over-read vulnerability in Leptonica image processing library versions before 1.80.0. The flaw in rasteropGener...

Mar 12, 2021
CVE-2020-36223
7.5

This vulnerability in OpenLDAP's slapd daemon allows attackers to trigger a crash through malformed Values Return Filter control requests, causing den...

Jan 26, 2021
CVE-2020-11214
7.5

This vulnerability is a buffer over-read in Qualcomm Snapdragon firmware when processing NDL attributes with unexpected length. It allows reading beyo...

Jan 21, 2021
CVE-2020-9094
7.5

This CVE describes an out-of-bounds read vulnerability in Huawei CloudEngine products. Attackers can exploit it by sending malicious packets, potentia...

Dec 29, 2020
CVE-2020-24340
7.5

This vulnerability in picoTCP and picoTCP-NG allows attackers to cause denial-of-service through out-of-bounds memory reads and invalid pointer derefe...

Dec 11, 2020
CVE-2020-17445
7.5

This vulnerability in picoTCP 1.7.0 allows attackers to cause an out-of-bounds read when processing IPv6 destination options due to insufficient lengt...

Dec 11, 2020
CVE-2020-26269
7.5

This CVE describes an out-of-bounds memory access vulnerability in TensorFlow's file path globbing implementation. Attackers could potentially read or...

Dec 10, 2020
CVE-2020-5675
7.5

An out-of-bounds read vulnerability in Mitsubishi Electric GOT2000/GS21 series GT21/GS21 models and Tension Controller LE7-40GU-L series allows remote...

Dec 4, 2020
CVE-2020-8754
7.5

CVE-2020-8754 is an out-of-bounds read vulnerability in Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM) subsystems. It...

Nov 12, 2020
CVE-2020-26566
7.5

CVE-2020-26566 is a denial-of-service vulnerability in Motion-Project Motion's web interface (webu.c) that allows remote unauthenticated attackers to ...

Oct 26, 2020
CVE-2020-9828
7.5

CVE-2020-9828 is an out-of-bounds read vulnerability in macOS that allows a remote attacker to potentially leak sensitive user information. This affec...

Oct 22, 2020
CVE-2020-24387
7.5

This vulnerability in yubihsm-shell allows attackers to cause out-of-bounds memory operations by exploiting unchecked session IDs returned from YubiHS...

Oct 19, 2020
CVE-2020-0413
7.5

This vulnerability allows remote attackers to read memory beyond intended boundaries in Android's Bluetooth stack, potentially exposing sensitive info...

Oct 14, 2020
CVE-2020-0300
7.5

This CVE describes an out-of-bounds read vulnerability in Android's NFC stack due to uninitialized data. It allows remote attackers to potentially rea...

Sep 18, 2020
CVE-2020-9717
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read sensitive memory contents. Succe...

Aug 19, 2020
CVE-2020-9719
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read sensitive memory contents. Succe...

Aug 19, 2020
CVE-2020-9721
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read memory contents they shouldn't a...

Aug 19, 2020
CVE-2020-9723
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read sensitive memory contents. Succe...

Aug 19, 2020
CVE-2020-24372
7.5

CVE-2020-24372 is an out-of-bounds read vulnerability in LuaJIT's error handling code that could allow attackers to read sensitive memory contents. Th...

Aug 17, 2020
CVE-2020-12674
7.5

CVE-2020-12674 is a buffer overflow vulnerability in Dovecot's authentication service where a specially crafted RPA request with zero length causes a ...

Aug 12, 2020
CVE-2020-0251
7.5

CVE-2020-0251 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory da...

Aug 11, 2020
CVE-2020-0254
7.5

CVE-2020-0254 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory co...

Aug 11, 2020
CVE-2020-3700
7.5

CVE-2020-3700 is an out-of-bounds read vulnerability in Qualcomm Snapdragon Wi-Fi drivers that could allow local attackers to read sensitive kernel me...

Jul 30, 2020
CVE-2020-14676
7.5

This CVE-2020-14676 is an out-of-bounds read vulnerability (CWE-125) in Oracle VM VirtualBox Core component that allows a high-privileged attacker wit...

Jul 15, 2020
CVE-2020-15572
7.5

This vulnerability is an out-of-bounds memory access in Tor versions before 0.4.3.6 when built with Mozilla NSS. It allows remote attackers to cause a...

Jul 15, 2020
CVE-2020-10037
7.5

A memory read vulnerability in Siemens SICAM devices allows attackers to perform flooding attacks against the web server, potentially exposing confide...

Jul 14, 2020
CVE-2020-9625
7.5

Adobe DNG SDK versions 1.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. This ...

Jun 26, 2020
CVE-2020-9628
7.5

Adobe DNG SDK versions 1.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. This ...

Jun 26, 2020
CVE-2020-9623
7.5

This vulnerability in Adobe DNG SDK allows attackers to read memory beyond intended boundaries, potentially exposing sensitive information. It affects...

Jun 26, 2020
CVE-2020-9599
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read sensitive memory contents. Succe...

Jun 25, 2020
CVE-2020-9601
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat and Reader that could allow attackers to read sensitive memory contents. Succe...

Jun 25, 2020
CVE-2020-14163
7.5

This CVE describes a use-after-free vulnerability in JerryScript's garbage collector that can lead to memory corruption. Attackers could exploit this ...

Jun 15, 2020
CVE-2019-20838
7.5

This vulnerability in libpcre (PCRE library) allows attackers to read beyond allocated memory buffers when processing certain regular expressions with...

Jun 15, 2020
CVE-2020-0214
7.5

CVE-2020-0214 is an out-of-bounds read vulnerability in Android's NFC stack that could allow remote information disclosure without user interaction. I...

Jun 11, 2020
CVE-2020-0140
7.5

This vulnerability in Android's NFC stack allows remote information disclosure without user interaction. Attackers can exploit a missing bounds check ...

Jun 11, 2020
CVE-2020-0142
7.5

This vulnerability in Android's NFC stack allows remote information disclosure without user interaction. Attackers can exploit a missing bounds check ...

Jun 11, 2020
CVE-2020-0128
7.5

This CVE describes an integer overflow vulnerability in Android's AMPEG4ElementaryAssembler component that leads to an out-of-bounds read. Attackers c...

Jun 11, 2020
CVE-2020-9837
7.5

CVE-2020-9837 is an out-of-bounds read vulnerability in Apple operating systems that allows a remote attacker to leak memory, potentially exposing sen...

Jun 9, 2020
CVE-2020-1763
7.5

An unauthenticated attacker can crash the libreswan pluto daemon by sending specially-crafted IKEv1 Informational Exchange packets, causing a denial o...

May 12, 2020
CVE-2020-12783
7.5

CVE-2020-12783 is an out-of-bounds read vulnerability in Exim's SPA/NTLM authentication module that could allow authentication bypass. Attackers could...

May 11, 2020
CVE-2020-12018
7.5

An out-of-bounds read vulnerability in Advantech WebAccess Node allows attackers to read unauthorized data from memory. This affects industrial contro...

May 8, 2020
CVE-2020-3298
7.5

An unauthenticated remote attacker can cause Cisco ASA and FTD devices to reload by sending malformed OSPF packets, resulting in denial of service. Th...

May 6, 2020
CVE-2017-18688
7.5

This vulnerability allows attackers to read sensitive memory locations outside intended buffers on Samsung mobile devices. It affects Samsung devices ...

Apr 7, 2020
CVE-2020-3777
7.5

This CVE describes an out-of-bounds read vulnerability in Adobe Photoshop that could allow attackers to read sensitive memory content. Affected users ...

Mar 25, 2020
CVE-2020-6077
7.5

CVE-2020-6077 is an out-of-bounds read vulnerability in Videolabs libmicrodns 0.1.0 that allows remote attackers to cause denial of service by sending...

Mar 24, 2020

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,859 CVEs classified as CWE-125, with 198 rated critical and 1,113 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free