CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,875
Total CVEs
203
Critical
1,118
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 300
2 Adobe 173
3 Google 167
4 Microsoft 113
5 Apple 109
6 Debian 96
7 Siemens 63
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 50

All Out-of-bounds Read CVEs (1,875)

CVE-2025-37749
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's PPP (Point-to-Point Protocol) implementation. When processing short or em...

May 1, 2025
CVE-2025-23156
7.1

This vulnerability in the Linux kernel's Venus media driver allows out-of-bounds memory access when parsing HFI packets. Attackers could potentially r...

May 1, 2025
CVE-2025-39735
7.1

This CVE describes an integer overflow vulnerability in the Linux kernel's JFS filesystem extended attribute handling. When processing specially craft...

Apr 18, 2025
CVE-2025-39778
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's NVMe over Fabrics (NVMe-oF) subsystem. The vulnerability allows reading b...

Apr 18, 2025
CVE-2025-37785
7.1

A memory corruption vulnerability in the Linux kernel's ext4 filesystem allows out-of-bounds read when processing corrupted directories. Attackers wit...

Apr 18, 2025
CVE-2025-22118
7.1

This CVE addresses an out-of-bounds memory access vulnerability in the Linux kernel's Intel Ethernet Connection Controller (ice) driver. An attacker c...

Apr 16, 2025
CVE-2025-22121
7.1

This is a use-after-free vulnerability in the Linux kernel's ext4 filesystem driver that allows reading kernel memory beyond allocated bounds. It affe...

Apr 16, 2025
CVE-2025-22112
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's Broadcom NetXtreme Ethernet driver (bnxt). An attacker could pot...

Apr 16, 2025
CVE-2025-22104
7.1

A buffer overflow vulnerability in the IBM vNIC driver for Linux kernel allows reading beyond allocated memory boundaries when printing hex dumps. Thi...

Apr 16, 2025
CVE-2025-22107
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's SJA1105 DSA driver. When deleting table entries, the driver inco...

Apr 16, 2025
CVE-2025-22079
7.1

This CVE-2025-22079 is an out-of-bounds read/write vulnerability in the Linux kernel's OCFS2 filesystem driver. Attackers could potentially cause kern...

Apr 16, 2025
CVE-2025-22087
7.1

A Linux kernel vulnerability in the BPF subsystem where the may_goto instruction uses extra stack space, causing array bounds errors when calculating ...

Apr 16, 2025
CVE-2025-22038
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ksmbd SMB server module. An attacker could exploit this to read kernel me...

Apr 16, 2025
CVE-2025-21993
7.1

This CVE addresses an undefined behavior shift-out-of-bounds vulnerability in the Linux kernel's iSCSI iBFT driver when using IPv6. The vulnerability ...

Apr 2, 2025
CVE-2025-21985
7.1

This CVE describes an out-of-bounds memory access vulnerability in the AMD display driver component of the Linux kernel. Attackers could exploit this ...

Apr 1, 2025
CVE-2025-21905
7.1

This CVE describes an out-of-bounds read vulnerability in the iwlwifi driver in the Linux kernel. When reading firmware files without proper null term...

Apr 1, 2025
CVE-2022-49738
7.1

This is a Linux kernel vulnerability in the F2FS filesystem garbage collection code where missing sanity checks on i_extra_isize values can lead to ou...

Mar 27, 2025
CVE-2022-49740
7.1

This vulnerability is an out-of-bounds read in the Broadcom FullMAC WiFi driver (brcmfmac) in the Linux kernel. It allows attackers to read kernel mem...

Mar 27, 2025
CVE-2024-44199
7.1

This CVE describes an out-of-bounds read vulnerability in macOS that could allow a malicious application to read kernel memory or cause system crashes...

Mar 21, 2025
CVE-2025-22226
KEV 7.1

This vulnerability allows attackers with administrative privileges on a virtual machine to read memory from the host's vmx process, potentially exposi...

Mar 4, 2025
CVE-2025-21815
7.1

A Linux kernel memory management vulnerability where improper bounds checking in the compaction subsystem could allow shift-out-of-bounds operations. ...

Feb 27, 2025
CVE-2025-21794
7.1

A stack-out-of-bounds read vulnerability in the Linux kernel's hid-thrustmaster driver allows reading beyond allocated memory boundaries. This affects...

Feb 27, 2025
CVE-2025-21782
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's orangefs_debug_write function. Attackers with local access could potentia...

Feb 27, 2025
CVE-2025-21789
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's LoongArch checksum optimization code when processing negative length valu...

Feb 27, 2025
CVE-2025-21741
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ipheth USB network driver. An attacker could exploit this to read kernel ...

Feb 27, 2025
CVE-2025-21742
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's usbnet ipheth driver for iOS tethering. Attackers could exploit this to r...

Feb 27, 2025
CVE-2025-21743
7.1

A buffer overflow vulnerability in the Linux kernel's USB network driver for iPhone tethering (ipheth) could allow out-of-bounds memory reads. This af...

Feb 27, 2025
CVE-2024-58014
7.1

This CVE addresses an out-of-bounds read vulnerability in the brcmsmac WiFi driver in the Linux kernel. The vulnerability could allow local attackers ...

Feb 27, 2025
CVE-2024-58015
7.1

This vulnerability in the Linux kernel's ath12k WiFi driver allows an attacker to cause out-of-bounds memory access by exploiting a buffer size calcul...

Feb 27, 2025
CVE-2024-58007
7.1

This vulnerability in the Linux kernel's Qualcomm SOC info driver allows an out-of-bounds read of memory when accessing the serial number on MSM8916 d...

Feb 27, 2025
CVE-2025-21717
7.1

This vulnerability in the Linux kernel's mlx5e network driver allows out-of-bounds memory access when performing ethtool or netlink operations on syst...

Feb 27, 2025
CVE-2025-21719
7.1

A memory corruption vulnerability in the Linux kernel's IP multicast routing (ipmr) subsystem allows a local attacker to trigger a kernel crash (denia...

Feb 27, 2025
CVE-2024-57982
7.1

This CVE describes a race condition vulnerability in the Linux kernel's XFRM (IPsec) subsystem where parallel hash table operations during state looku...

Feb 27, 2025
CVE-2022-49706
7.1

A race condition vulnerability in the Linux kernel's zonefs filesystem driver causes a kernel warning and potential denial-of-service when reading fro...

Feb 26, 2025
CVE-2022-49674
7.1

This CVE is an out-of-bounds memory access vulnerability in the Linux kernel's dm-raid subsystem. It allows attackers with local access to potentially...

Feb 26, 2025
CVE-2022-49623
7.1

This CVE-2022-49623 is a memory corruption vulnerability in the Linux kernel's PowerPC XIVE interrupt controller implementation. It allows attackers t...

Feb 26, 2025
CVE-2022-49560
7.1

A memory corruption vulnerability in the Linux kernel's exFAT filesystem driver allows out-of-bounds read/write operations when handling invalid clust...

Feb 26, 2025
CVE-2022-49551
7.1

This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's USB ISP1760 host controller driver. The vulnerability allows read...

Feb 26, 2025
CVE-2022-49515
7.1

This CVE describes an out-of-bounds memory access vulnerability in the CS35L41 audio codec driver in the Linux kernel. An attacker could potentially c...

Feb 26, 2025
CVE-2022-49518
7.1

This CVE-2022-49518 is an out-of-bounds memory access vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem. It allows attackers to ...

Feb 26, 2025
CVE-2022-49503
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's ath9k_htc wireless driver. An attacker could potentially cause a...

Feb 26, 2025
CVE-2022-49444
7.1

This Linux kernel vulnerability allows out-of-bounds memory access when loading specially crafted kernel modules. Attackers with local access can trig...

Feb 26, 2025
CVE-2022-49407
7.1

This CVE-2022-49407 is a memory corruption vulnerability in the Linux kernel's Distributed Lock Manager (DLM) component where improper casting between...

Feb 26, 2025
CVE-2022-49395
7.1

This is an out-of-bounds read vulnerability in the Linux kernel's User Mode Linux (UML) subsystem. It occurs when setting up Local Descriptor Table (L...

Feb 26, 2025
CVE-2022-49401
7.1

This CVE-2022-49401 is a buffer overflow vulnerability in the Linux kernel's page_owner subsystem where strlcpy() is used incorrectly with current->co...

Feb 26, 2025
CVE-2022-49368
7.1

This vulnerability allows an attacker with local user access to trigger an out-of-bounds read in the MediaTek Ethernet driver in the Linux kernel. It ...

Feb 26, 2025
CVE-2022-49252
7.1

This CVE involves an out-of-bounds array access vulnerability in the Linux kernel's ASoC rx-macro codec driver. On 64-bit ARM (aarch64) systems, impro...

Feb 26, 2025
CVE-2022-49249
7.1

This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's wc938x audio codec driver. On ARM64 (aarch64) systems where sizeo...

Feb 26, 2025
CVE-2022-49250
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's ASoC (Audio System on Chip) codec driver for rx-macro. The flaw ...

Feb 26, 2025
CVE-2022-49234
7.1

A vulnerability in the Linux kernel's Distributed Switch Architecture (DSA) subsystem allows array out-of-bounds accesses when VLAN filtering changes ...

Feb 26, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,875 CVEs classified as CWE-125, with 203 rated critical and 1,118 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free