CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,691
Total CVEs
145
Critical
998
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 158
3 Google 147
4 Microsoft 113
5 Apple 86
6 Debian 80
7 Siemens 59
8 Pdf Xchange 58
9 Samsung 50
10 Fedoraproject 36

All Out-of-bounds Read CVEs (1,691)

CVE-2020-25109
9.8

This vulnerability in Ethernut's DNS implementation allows attackers to send malformed DNS packets that trigger memory corruption. Successful exploita...

Dec 11, 2020
CVE-2019-8746
9.8

CVE-2019-8746 is a critical out-of-bounds read vulnerability in multiple Apple products that allows remote attackers to cause application crashes or e...

Oct 27, 2020
CVE-2019-8547
9.8

CVE-2019-8547 is an out-of-bounds read vulnerability in Apple operating systems that allows remote attackers to leak kernel memory. This could expose ...

Oct 27, 2020
CVE-2019-8581
9.8

CVE-2019-8581 is an out-of-bounds read vulnerability in Apple AirPort Base Station firmware that allows remote attackers to leak memory contents. This...

Oct 27, 2020
CVE-2020-9918
9.8

CVE-2020-9918 is a critical kernel vulnerability in Apple operating systems that allows remote attackers to read beyond allocated memory boundaries. T...

Oct 16, 2020
CVE-2020-25021
9.8

This vulnerability in Noise-Java allows out-of-bounds memory access in the ChaChaPolyCipherState.encryptWithAd() function due to insufficient boundary...

Sep 4, 2020
CVE-2020-25023
9.8

This vulnerability in Noise-Java allows out-of-bounds memory access in the AESGCMOnCtrCipherState.encryptWithAd() function due to insufficient boundar...

Sep 4, 2020
CVE-2023-3110
9.6

An unauthenticated attacker within Z-Wave range can exploit a stack buffer overflow in SiLabs Unify Gateway versions 1.3.1 and earlier to execute arbi...

Jun 21, 2023
CVE-2025-64656
9.4

This vulnerability allows an unauthorized attacker to perform an out-of-bounds read in Application Gateway, potentially leading to privilege escalatio...

Nov 26, 2025
CVE-2023-4280
9.3

This vulnerability allows attackers to bypass TrustZone memory isolation in Silicon Labs Gecko SDK, enabling unauthorized access to trusted memory reg...

Jan 2, 2024
CVE-2022-2010
9.3

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to potentially escape the browser sandbox via a craf...

Jul 28, 2022
CVE-2026-3061
9.1

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's media component by tricking a user into visiting a ...

Feb 23, 2026
CVE-2026-25139
9.1

CVE-2026-25139 is an out-of-bounds read vulnerability in RIOT OS's 6LoWPAN stack that allows unauthenticated attackers to read adjacent memory or cras...

Feb 4, 2026
CVE-2026-22855
9.1

A heap out-of-bounds read vulnerability in FreeRDP's smartcard SetAttrib path allows attackers to read memory beyond allocated buffers. This affects F...

Jan 14, 2026
CVE-2026-22858
9.1

This CVE describes a global buffer overflow vulnerability in FreeRDP's Base64 decoding implementation. On Arm/AArch64 architectures, signedness issues...

Jan 14, 2026
CVE-2026-22859
9.1

This vulnerability in FreeRDP allows remote attackers to cause an out-of-bounds read by sending specially crafted MSUSB_INTERFACE_DESCRIPTOR values. T...

Jan 14, 2026
CVE-2025-68118
9.1

This vulnerability in FreeRDP allows attackers to cause heap-based out-of-bounds memory reads by controlling hostnames in certificate cache filenames....

Dec 17, 2025
CVE-2025-66589
9.1

An out-of-bounds read vulnerability in AzeoTech DAQFactory allows attackers to read memory beyond allocated buffers, potentially exposing sensitive in...

Dec 11, 2025
CVE-2025-66409
9.1

This vulnerability in ESP-IDF Bluetooth stack allows an attacker to trigger an out-of-bounds read by sending a malformed VENDOR DEPENDENT command when...

Dec 2, 2025
CVE-2025-61043
9.1

An out-of-bounds read vulnerability in Monkey's Audio 11.31 allows attackers to read beyond allocated memory boundaries when processing UTF-8 strings....

Oct 28, 2025
CVE-2025-55100
9.1

This vulnerability allows attackers to read memory beyond allocated boundaries in USBX's audio class parsing function. It affects systems using Eclips...

Oct 17, 2025
CVE-2024-25178
9.1

This vulnerability is an out-of-bounds read in the stack-overflow handler of LuaJIT, which could allow attackers to read sensitive memory contents or ...

Jul 7, 2025
CVE-2025-53074
9.1

An out-of-bounds read vulnerability in Samsung's rLottie animation library (version 0.2) allows attackers to read memory beyond allocated buffers. Thi...

Jun 30, 2025
CVE-2025-48706
9.1

An out-of-bounds read vulnerability in COROS PACE 3 devices allows attackers to cause denial of service by sending crafted BLE messages that force dev...

Jun 20, 2025
CVE-2025-49796
9.1

A memory corruption vulnerability in libxml2 allows attackers to craft malicious XML files containing specific sch:name elements. This can cause libxm...

Jun 16, 2025
CVE-2025-27891
9.1

A memory corruption vulnerability in Samsung Exynos processors allows attackers to perform out-of-bounds reads via malformed NAS packets. This affects...

May 14, 2025
CVE-2024-35532
9.1

An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea allows attackers to read arbitrary files, make server-side request forgery...

Jan 7, 2025
CVE-2024-47774
9.1

This CVE describes an out-of-bounds read vulnerability in GStreamer's subtitle parsing function. Attackers could exploit this to read sensitive memory...

Dec 12, 2024
CVE-2024-47776
9.1

CVE-2024-47776 is an out-of-bounds read vulnerability in GStreamer's WAV file parser that occurs when processing malformed CUE chunks. This allows att...

Dec 12, 2024
CVE-2024-47597
9.1

This CVE describes an out-of-bounds read vulnerability in GStreamer's qtdemux component when parsing MP4 files. Attackers can craft malicious MP4 file...

Dec 12, 2024
CVE-2024-47600
9.1

This CVE describes an out-of-bounds read vulnerability in GStreamer's audio channel discovery function. Attackers can trigger memory corruption by pro...

Dec 12, 2024
CVE-2024-37371
9.1

This vulnerability in MIT Kerberos 5 allows attackers to trigger invalid memory reads by sending specially crafted GSS message tokens with invalid len...

Jun 28, 2024
CVE-2024-5535
9.1

This OpenSSL vulnerability allows up to 255 bytes of arbitrary private memory data to be sent to a peer when SSL_select_next_proto is called with an e...

Jun 27, 2024
CVE-2024-37407
9.1

This vulnerability in Libarchive allows out-of-bounds memory access when processing ZIP archives with empty filenames and macOS extended attributes en...

Jun 8, 2024
CVE-2024-24192
9.1

CVE-2024-24192 is a heap overflow vulnerability in robdns that occurs when processing zone files. Attackers can exploit this to execute arbitrary code...

Jun 6, 2024
CVE-2024-22949
9.1

CVE-2024-22949 is a disputed vulnerability in JFreeChart v1.5.4 where a NullPointerException occurs in the CategoryLineAnnotation component, potential...

Apr 8, 2024
CVE-2022-48623
9.1

CVE-2022-48623 is an out-of-bounds read vulnerability in Cpanel::JSON::XS Perl package versions before 4.33. Attackers can exploit this to read sensit...

Feb 13, 2024
CVE-2023-40436
9.1

This is a macOS kernel vulnerability where improper bounds checking allows attackers to read kernel memory or cause system crashes. It affects macOS s...

Sep 27, 2023
CVE-2023-41359
9.1

CVE-2023-41359 is an out-of-bounds read vulnerability in FRRouting FRR's BGP daemon that occurs during AIGP attribute validation. Attackers could expl...

Aug 29, 2023
CVE-2023-38426
9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond allocated buffers when processing SMB2 create context...

Jul 18, 2023
CVE-2023-38428
9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond intended boundaries by exploiting improper validation...

Jul 18, 2023
CVE-2023-38430
9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to trigger an out-of-bounds read by sending specially crafted SMB requests ...

Jul 18, 2023
CVE-2023-38432
9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to trigger an out-of-bounds read by sending specially crafted SMB packets w...

Jul 18, 2023
CVE-2023-37240
9.1

CVE-2023-37240 is an out-of-bounds read vulnerability in Huawei's distributed file system caused by missing input length verification. Successful expl...

Jul 6, 2023
CVE-2023-2989
9.1

This vulnerability in Fortra Globalscape EFT administration server allows attackers to read memory outside allocated bounds, potentially causing servi...

Jun 22, 2023
CVE-2023-2838
9.1

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents or cause den...

May 22, 2023
CVE-2022-48312
9.1

CVE-2022-48312 is an out-of-bounds read/write vulnerability in Huawei's HwPCAssistant module that could allow attackers to read or modify memory conte...

Apr 16, 2023
CVE-2022-34029
9.1

CVE-2022-34029 is an out-of-bounds read vulnerability in Nginx NJS (JavaScript engine) that could allow attackers to read sensitive memory contents or...

Jul 18, 2022
CVE-2022-35409
9.1

This vulnerability in Mbed TLS allows unauthenticated attackers to send specially crafted DTLS ClientHello messages to servers with specific configura...

Jul 15, 2022
CVE-2022-1899
9.1

CVE-2022-1899 is an out-of-bounds read vulnerability in radare2, a popular reverse engineering framework. This vulnerability allows attackers to read ...

May 26, 2022

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,691 CVEs classified as CWE-125, with 145 rated critical and 998 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free