CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,859
Total CVEs
198
Critical
1,113
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
98
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,859)

CVE-2019-19945
7.5

This vulnerability in uhttpd (OpenWrt's web server) allows attackers to cause a heap buffer overflow by sending specially crafted HTTP POST requests w...

Mar 16, 2020
CVE-2019-9473
7.5

This Bluetooth vulnerability in Android 10 allows attackers to read memory beyond intended boundaries without user interaction, potentially exposing s...

Mar 15, 2020
CVE-2020-1863
7.5

This CVE describes an out-of-bounds read vulnerability in Huawei USG6000V firewall software due to a logical flaw in JSON parsing. Remote, unauthentic...

Mar 12, 2020
CVE-2020-0038
7.5

This vulnerability in Android's NFC stack allows attackers to read uninitialized memory data remotely without user interaction. It affects Android dev...

Mar 10, 2020
CVE-2020-0034
7.5

This CVE describes an out-of-bounds read vulnerability in Android's VP8 video decoder. An attacker could remotely disclose information from affected d...

Mar 10, 2020
CVE-2020-1893
7.5

CVE-2020-1893 is an out-of-bounds read vulnerability in HHVM's JSON parsing that occurs due to insufficient boundary checks. When exploited, it can ca...

Mar 3, 2020
CVE-2020-1888
7.5

CVE-2020-1888 is an out-of-bounds memory read vulnerability in HHVM's JSON decoder that occurs when processing backslash characters. This can cause de...

Mar 3, 2020
CVE-2025-13735
7.4

An out-of-bounds read vulnerability in ASR Lapwing_Linux affects ASR1903 and ASR3901 devices running the nr_fw module. This allows attackers to read m...

Nov 26, 2025
CVE-2025-35967
7.4

An out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows unprivileged attackers on the same network to cause deni...

Nov 11, 2025
CVE-2025-49480
7.4

This CVE describes an out-of-bounds memory access vulnerability in the LZMA compression library used in ASR180x and ASR190x LTE telephony modules. Att...

Jul 1, 2025
CVE-2025-1254
7.4

This vulnerability in RTI Connext Professional Recording Service allows attackers to read or write data outside intended memory buffers, potentially l...

May 8, 2025
CVE-2025-32914
7.4

CVE-2025-32914 is an out-of-bounds read vulnerability in libsoup's soup_multipart_new_from_message() function. It allows malicious HTTP clients to cau...

Apr 14, 2025
CVE-2024-11614
7.4

This CVE-2024-11614 is an out-of-bounds read vulnerability in DPDK's Vhost library checksum offload feature. It allows a malicious virtual machine usi...

Dec 18, 2024
CVE-2024-36054
7.4

This vulnerability in Hw64.sys driver allows unprivileged user-mode processes to read arbitrary kernel memory through specific IOCTL calls, potentiall...

May 26, 2024
CVE-2021-3712
7.4

This OpenSSL vulnerability allows attackers to cause buffer overruns when applications directly construct ASN.1 strings without proper NUL termination...

Aug 24, 2021
CVE-2021-21198
7.4

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to perform an out-of-bounds read in IPC (Inter-Proce...

Apr 9, 2021
CVE-2023-34101
7.3

This vulnerability in Contiki-NG OS allows attackers to trigger out-of-bounds memory reads by sending specially crafted truncated ICMP DAO packets. Io...

Jun 14, 2023
CVE-2023-34100
7.3

This CVE describes a buffer overflow vulnerability in Contiki-NG's TCP MSS option parsing for IPv6 packets. Attackers can trigger out-of-bounds memory...

Jun 9, 2023
CVE-2021-25487
7.3

This vulnerability in Samsung modem interface drivers allows out-of-bounds memory read and arbitrary code execution through invalid function pointer d...

Oct 6, 2021
CVE-2021-37654
7.3

This vulnerability in TensorFlow allows attackers to trigger crashes or read data outside allocated memory bounds via the ResourceGather API. It affec...

Aug 12, 2021
CVE-2021-37635
7.3

This vulnerability in TensorFlow allows attackers to trigger out-of-bounds memory accesses during sparse reduction operations, potentially leading to ...

Aug 12, 2021
CVE-2024-38028
7.2

CVE-2024-38028 is a remote code execution vulnerability in Microsoft Windows Performance Data Helper Library. Attackers can exploit this vulnerability...

Jul 9, 2024
CVE-2024-32631
7.2

CVE-2024-32631 is an out-of-bounds read vulnerability in the ciCCIOTOPT component of ASR180X chipsets that can cause incorrect computations. This affe...

Apr 16, 2024
CVE-2026-27692
7.1

A heap buffer overflow vulnerability in iccDEV allows reading past allocated memory boundaries when parsing ICC profile XML text description tags. Thi...

Feb 25, 2026
CVE-2026-20611
7.1

This CVE describes an out-of-bounds memory access vulnerability in Apple's media file processing across multiple operating systems. Attackers can craf...

Feb 11, 2026
CVE-2026-22984
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's libceph component within the handle_auth_done() function. Attackers could...

Jan 23, 2026
CVE-2025-64893
7.1

CVE-2025-64893 is an out-of-bounds read vulnerability in Adobe DNG SDK versions 1.7.0 and earlier. Attackers can exploit this by tricking users into o...

Dec 9, 2025
CVE-2025-66293
7.1

CVE-2025-66293 is an out-of-bounds read vulnerability in libpng's simplified API that allows reading up to 1012 bytes beyond allocated memory when pro...

Dec 3, 2025
CVE-2025-64720
7.1

This CVE describes an out-of-bounds read vulnerability in LIBPNG library versions 1.6.0 through 1.6.50. When processing palette images with PNG_FLAG_O...

Nov 25, 2025
CVE-2025-62202
7.1

An out-of-bounds read vulnerability in Microsoft Office Excel allows an attacker to read memory contents beyond intended boundaries, potentially expos...

Nov 11, 2025
CVE-2025-60726
7.1

This vulnerability is an out-of-bounds read flaw in Microsoft Excel that allows an attacker to read memory contents they shouldn't have access to. Att...

Nov 11, 2025
CVE-2023-53675
7.1

This CVE-2023-53675 is an out-of-bounds read vulnerability in the Linux kernel's SCSI Enclosure Services (SES) driver. It allows attackers to read ker...

Oct 7, 2025
CVE-2023-53668
7.1

This CVE describes a denial-of-service vulnerability in the Linux kernel's ring buffer tracing subsystem. When reading from trace_pipe, a race conditi...

Oct 7, 2025
CVE-2023-53659
7.1

This vulnerability in the Linux kernel's iavf driver allows an out-of-bounds memory access when setting network channels during device removal. Attack...

Oct 7, 2025
CVE-2022-50551
7.1

This CVE describes a shift-out-of-bounds vulnerability in the brcmfmac WiFi driver in the Linux kernel. An attacker could potentially cause a kernel p...

Oct 7, 2025
CVE-2023-53600
7.1

A memory corruption vulnerability in the Linux kernel's tunneling code allows attackers to trigger a kernel panic (denial of service) when the kernel ...

Oct 4, 2025
CVE-2023-53575
7.1

This CVE describes an array out-of-bounds access vulnerability in the iwlwifi driver in the Linux kernel. An attacker could potentially exploit this t...

Oct 4, 2025
CVE-2022-50508
7.1

This vulnerability is an out-of-bounds memory access flaw in the MediaTek MT76 Wi-Fi driver for Linux kernel. It allows attackers with local access to...

Oct 4, 2025
CVE-2022-50490
7.1

A race condition vulnerability in the Linux kernel's BPF subsystem allows improper error handling during hash table operations. When htab_lock_bucket(...

Oct 4, 2025
CVE-2025-39943
7.1

A memory corruption vulnerability in the Linux kernel's ksmbd SMB server component allows attackers to trigger out-of-bounds memory access by sending ...

Oct 4, 2025
CVE-2023-53521
7.1

A slab-out-of-bounds read vulnerability in the Linux kernel's SCSI Enclosure Services (SES) driver allows reading kernel memory beyond allocated bound...

Oct 1, 2025
CVE-2023-53486
7.1

CVE-2023-53486 is an out-of-bounds read vulnerability in the Linux kernel's NTFS3 filesystem driver. It allows attackers to read kernel memory beyond ...

Oct 1, 2025
CVE-2023-53465
7.1

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's Qualcomm SoundWire driver. An attacker could exploit this to corrupt ker...

Oct 1, 2025
CVE-2022-50442
7.1

CVE-2022-50442 is an out-of-bounds read vulnerability in the Linux kernel's NTFS3 filesystem driver. It occurs when parsing index buffers during direc...

Oct 1, 2025
CVE-2021-4460
7.1

This CVE describes an undefined behavior shift operation vulnerability in the AMD GPU kernel driver (drm/amdkfd) in the Linux kernel. When certain que...

Oct 1, 2025
CVE-2025-39922
7.1

A memory corruption vulnerability in the Linux kernel's ixgbe network driver allows incorrect memory access when handling Energy Efficient Ethernet (E...

Oct 1, 2025
CVE-2025-39901
7.1

This CVE describes a vulnerability in the Linux kernel's i40e network driver where debugfs files have insecure read handlers that could allow reading ...

Oct 1, 2025
CVE-2025-39853
7.1

This CVE describes a memory access vulnerability in the Linux kernel's i40e network driver. When the MAC address list is empty, the driver uses list_f...

Sep 19, 2025
CVE-2025-39839
7.1

This vulnerability in the Linux kernel's batman-adv network coding module allows out-of-bounds memory read/write operations. Attackers could potential...

Sep 19, 2025
CVE-2023-53420
7.1

A memory corruption vulnerability in the Linux kernel's NTFS3 filesystem driver allows attackers to trigger a kernel panic or potentially execute arbi...

Sep 18, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,859 CVEs classified as CWE-125, with 198 rated critical and 1,113 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free