CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,864
Total CVEs
198
Critical
1,118
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
103
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 95
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,864)

CVE-2025-39922
7.1

A memory corruption vulnerability in the Linux kernel's ixgbe network driver allows incorrect memory access when handling Energy Efficient Ethernet (E...

Oct 1, 2025
CVE-2025-39901
7.1

This CVE describes a vulnerability in the Linux kernel's i40e network driver where debugfs files have insecure read handlers that could allow reading ...

Oct 1, 2025
CVE-2025-39853
7.1

This CVE describes a memory access vulnerability in the Linux kernel's i40e network driver. When the MAC address list is empty, the driver uses list_f...

Sep 19, 2025
CVE-2025-39839
7.1

This vulnerability in the Linux kernel's batman-adv network coding module allows out-of-bounds memory read/write operations. Attackers could potential...

Sep 19, 2025
CVE-2023-53420
7.1

A memory corruption vulnerability in the Linux kernel's NTFS3 filesystem driver allows attackers to trigger a kernel panic or potentially execute arbi...

Sep 18, 2025
CVE-2023-53376
7.1

A memory corruption vulnerability in the Linux kernel's mpi3mr SCSI driver allows out-of-bounds memory access when managing bitmaps. This affects syst...

Sep 18, 2025
CVE-2022-50394
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's i2c subsystem, specifically in the ismt_access() function. Attac...

Sep 18, 2025
CVE-2023-53357
7.1

This CVE-2023-53357 is a slab-out-of-bounds read vulnerability in the Linux kernel's md/raid10 subsystem. It allows local attackers to read kernel mem...

Sep 17, 2025
CVE-2022-50366
7.1

This CVE is a Linux kernel vulnerability in the Intel RAPL power capping subsystem where improper input validation leads to an undefined behavior shif...

Sep 17, 2025
CVE-2023-53333
7.1

A stack-based buffer overflow vulnerability in the Linux kernel's netfilter DCCP conntrack module allows reading beyond allocated stack memory bounds....

Sep 16, 2025
CVE-2025-39817
7.1

A slab-out-of-bounds memory access vulnerability in the Linux kernel's efivarfs filesystem allows attackers to cause kernel memory corruption through ...

Sep 16, 2025
CVE-2025-39806
7.1

This vulnerability allows a malicious HID device to trigger a slab out-of-bounds memory access in the Linux kernel's multitouch driver. Attackers coul...

Sep 16, 2025
CVE-2023-53272
7.1

This CVE describes a shift-out-of-bounds vulnerability in the Linux kernel's ENA (Elastic Network Adapter) driver exponential backoff function. When n...

Sep 16, 2025
CVE-2023-53265
7.1

This CVE describes a slab out-of-bounds read vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem. The vulnerability occurs when ...

Sep 16, 2025
CVE-2023-53259
7.1

A NULL pointer dereference vulnerability in the Linux kernel's VMCI subsystem allows local attackers to cause a general protection fault (GPF) and pot...

Sep 15, 2025
CVE-2023-53254
7.1

This Linux kernel vulnerability allows out-of-bounds memory access when CPUs with different cache hierarchies share caches. It can lead to kernel cras...

Sep 15, 2025
CVE-2023-53238
7.1

This vulnerability is an out-of-bounds write in the Hisilicon PHY driver in the Linux kernel, caused by an incorrect boundary check in the hisi_inno_p...

Sep 15, 2025
CVE-2023-53222
7.1

A Linux kernel vulnerability in the JFS filesystem allows local attackers to cause a kernel crash (denial of service) through a shift-out-of-bounds er...

Sep 15, 2025
CVE-2023-53213
7.1

This CVE describes a slab-out-of-bounds read vulnerability in the Linux kernel's brcmfmac WiFi driver. An attacker could trigger this by sending speci...

Sep 15, 2025
CVE-2022-50333
7.1

This CVE-2022-50333 is a Linux kernel vulnerability in the JFS filesystem's dbDiscardAG function where improper bounds checking allows shift-out-of-bo...

Sep 15, 2025
CVE-2022-50307
7.1

This CVE-2022-50307 is an out-of-bounds read vulnerability in the Linux kernel's s390/cio subsystem. When devices are removed from the cio_ignore list...

Sep 15, 2025
CVE-2022-50279
7.1

This vulnerability is a global-out-of-bounds memory access bug in the Linux kernel's rtlwifi driver for Realtek wireless chips. It allows attackers to...

Sep 15, 2025
CVE-2022-50255
7.1

A memory safety vulnerability in the Linux kernel's tracing subsystem allows unprivileged local users to crash the kernel or potentially execute arbit...

Sep 15, 2025
CVE-2022-50239
7.1

A memory corruption vulnerability in the Linux kernel's Qualcomm CPU frequency driver allows writing to read-only memory regions. This can cause kerne...

Sep 15, 2025
CVE-2025-39786
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's AD7173 ADC driver. An attacker could potentially read or write k...

Sep 11, 2025
CVE-2025-39761
7.1

A memory corruption vulnerability in the Linux kernel's ath12k WiFi driver could allow out-of-bounds access when handling RX peer fragment setup error...

Sep 11, 2025
CVE-2025-39757
7.1

A Linux kernel vulnerability in the ALSA USB audio subsystem allows out-of-bounds memory access when processing malicious UAC3 audio device descriptor...

Sep 11, 2025
CVE-2025-39719
7.1

This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's BNO055 IMU driver. An attacker could potentially exploit this to ...

Sep 5, 2025
CVE-2025-39710
7.1

A memory safety vulnerability in the Linux kernel's Venus media driver allows potential out-of-bounds memory access when processing packets from firmw...

Sep 5, 2025
CVE-2025-39685
7.1

This CVE-2025-39685 is an out-of-bounds vulnerability in the Linux kernel's comedi pcl726 driver that allows local attackers to trigger a kernel crash...

Sep 5, 2025
CVE-2025-39680
7.1

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's RTL9300 I2C driver. An attacker with local access can trigger memory cor...

Sep 5, 2025
CVE-2025-38736
7.1

A Linux kernel vulnerability in the ASIX USB network driver allows invalid PHY addresses to be used during MDIO bus initialization, potentially causin...

Sep 5, 2025
CVE-2025-38728
7.1

A slab out-of-bounds read vulnerability in the Linux kernel's SMB3 implementation allows attackers to read kernel memory during mount operations to ks...

Sep 4, 2025
CVE-2025-38713
7.1

This is a memory corruption vulnerability in the Linux kernel's HFS+ filesystem driver. A slab-out-of-bounds read in the hfsplus_uni2asc() function ca...

Sep 4, 2025
CVE-2025-38715
7.1

A slab-out-of-bounds memory access vulnerability in the Linux kernel's HFS filesystem implementation allows attackers to read or write beyond allocate...

Sep 4, 2025
CVE-2025-38679
7.1

A Linux kernel vulnerability in the Venus media driver allows out-of-bounds memory reads when processing firmware messages. This could lead to kernel ...

Sep 4, 2025
CVE-2025-38677
7.1

This CVE-2025-38677 is an out-of-bounds memory access vulnerability in the Linux kernel's F2FS filesystem driver. It allows attackers with access to a...

Aug 30, 2025
CVE-2025-38652
7.1

A buffer overflow vulnerability in the Linux kernel's F2FS filesystem driver allows out-of-bounds memory access when mounting devices with paths exact...

Aug 22, 2025
CVE-2025-38636
7.1

This CVE describes a kernel memory access vulnerability in Linux's Runtime Verification (RV) subsystem where DA monitors tracepoints incorrectly read ...

Aug 22, 2025
CVE-2025-38616
7.1

A Linux kernel TLS vulnerability occurs when data is unexpectedly removed from the TCP socket receive queue while TLS is processing it, causing TLS to...

Aug 22, 2025
CVE-2025-38592
7.1

A use-after-free vulnerability in the Linux kernel's Bluetooth subsystem allows local attackers to cause memory corruption and potentially crash the k...

Aug 19, 2025
CVE-2025-38556
7.1

A vulnerability in the Linux kernel's HID core allows a shift-out-of-bounds exception when converting 32-bit quantities to 0-bit quantities. This coul...

Aug 19, 2025
CVE-2023-3865
7.1

A Linux kernel vulnerability in the ksmbd SMB server allows out-of-bounds read via specially crafted SMB2 write requests. This could lead to informati...

Aug 16, 2025
CVE-2023-3867
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ksmbd SMB server module. Attackers can exploit this by sending specially ...

Aug 16, 2025
CVE-2025-38529
7.1

This CVE describes an out-of-bounds bit shift vulnerability in the Linux kernel's comedi aio_iiro_16 driver. An attacker with local access can trigger...

Aug 16, 2025
CVE-2025-38502
7.1

This vulnerability in the Linux kernel allows an attacker to perform out-of-bounds memory access via BPF programs using cgroup local storage with tail...

Aug 16, 2025
CVE-2025-38497
7.1

This vulnerability in the Linux kernel's USB gadget configfs subsystem allows an out-of-bounds read when writing empty strings to specific sysfs attri...

Jul 28, 2025
CVE-2025-38482
7.1

This CVE describes an out-of-bounds bit shift vulnerability in the Linux kernel's comedi das6402 driver. An attacker with local access can trigger a k...

Jul 28, 2025
CVE-2025-38447
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's memory management subsystem. Attackers could potentially exploit...

Jul 25, 2025
CVE-2025-38445
7.1

A use-after-return vulnerability in the Linux kernel's RAID1 subsystem allows accessing stack memory after it has been freed. This can lead to kernel ...

Jul 25, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,864 CVEs classified as CWE-125, with 198 rated critical and 1,118 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free