CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,889
Total CVEs
203
Critical
1,132
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 301
2 Adobe 175
3 Google 167
4 Apple 113
5 Microsoft 113
6 Debian 98
7 Siemens 63
8 Pdf Xchange 58
9 Fedoraproject 52
10 Samsung 51

All Out-of-bounds Read CVEs (1,889)

CVE-2022-49515
7.1

This CVE describes an out-of-bounds memory access vulnerability in the CS35L41 audio codec driver in the Linux kernel. An attacker could potentially c...

Feb 26, 2025
CVE-2022-49518
7.1

This CVE-2022-49518 is an out-of-bounds memory access vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem. It allows attackers to ...

Feb 26, 2025
CVE-2022-49503
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's ath9k_htc wireless driver. An attacker could potentially cause a...

Feb 26, 2025
CVE-2022-49444
7.1

This Linux kernel vulnerability allows out-of-bounds memory access when loading specially crafted kernel modules. Attackers with local access can trig...

Feb 26, 2025
CVE-2022-49407
7.1

This CVE-2022-49407 is a memory corruption vulnerability in the Linux kernel's Distributed Lock Manager (DLM) component where improper casting between...

Feb 26, 2025
CVE-2022-49395
7.1

This is an out-of-bounds read vulnerability in the Linux kernel's User Mode Linux (UML) subsystem. It occurs when setting up Local Descriptor Table (L...

Feb 26, 2025
CVE-2022-49401
7.1

This CVE-2022-49401 is a buffer overflow vulnerability in the Linux kernel's page_owner subsystem where strlcpy() is used incorrectly with current->co...

Feb 26, 2025
CVE-2022-49368
7.1

This vulnerability allows an attacker with local user access to trigger an out-of-bounds read in the MediaTek Ethernet driver in the Linux kernel. It ...

Feb 26, 2025
CVE-2022-49252
7.1

This CVE involves an out-of-bounds array access vulnerability in the Linux kernel's ASoC rx-macro codec driver. On 64-bit ARM (aarch64) systems, impro...

Feb 26, 2025
CVE-2022-49249
7.1

This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's wc938x audio codec driver. On ARM64 (aarch64) systems where sizeo...

Feb 26, 2025
CVE-2022-49250
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's ASoC (Audio System on Chip) codec driver for rx-macro. The flaw ...

Feb 26, 2025
CVE-2022-49234
7.1

A vulnerability in the Linux kernel's Distributed Switch Architecture (DSA) subsystem allows array out-of-bounds accesses when VLAN filtering changes ...

Feb 26, 2025
CVE-2022-49218
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's DisplayPort helper code. An attacker could potentially read kernel memory...

Feb 26, 2025
CVE-2022-49163
7.1

This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's imx-jpeg media driver. When parsing malformed JPEG files, the dri...

Feb 26, 2025
CVE-2022-49145
7.1

This CVE-2022-49145 is an out-of-bounds memory access vulnerability in the Linux kernel's ACPI CPPC (Collaborative Processor Performance Control) subs...

Feb 26, 2025
CVE-2022-49094
7.1

This is a slab-out-of-bounds memory corruption vulnerability in the Linux kernel's TLS implementation. It allows attackers to potentially crash system...

Feb 26, 2025
CVE-2021-47633
7.1

This is an out-of-bounds write vulnerability in the Linux kernel's ath5k wireless driver. It allows attackers with local access to potentially crash t...

Feb 26, 2025
CVE-2021-47636
7.1

This is an out-of-bounds read vulnerability in the UBIFS filesystem implementation in the Linux kernel. An attacker could potentially read kernel memo...

Feb 26, 2025
CVE-2024-57945
7.1

A memory management vulnerability in the Linux kernel's RISC-V architecture implementation allows out-of-bounds memory access when initializing virtua...

Jan 21, 2025
CVE-2024-57928
7.1

This CVE-2024-57928 is a memory handling vulnerability in the Linux kernel's netfs subsystem that can cause denial-of-service conditions. When the ker...

Jan 19, 2025
CVE-2025-21647
7.1

A Linux kernel vulnerability in the CAKE scheduler (sch_cake) allows underflow of per-host bulk flow counters, leading to out-of-bounds memory access....

Jan 19, 2025
CVE-2024-52332
7.1

This vulnerability in the Linux kernel's igb network driver could allow invalid memory access when the driver fails to initialize properly. It affects...

Jan 11, 2025
CVE-2024-41935
7.1

A race condition vulnerability in the Linux kernel's F2FS filesystem could cause kernel hangs when shrinking large extent trees. This affects Linux sy...

Jan 11, 2025
CVE-2024-56721
7.1

A missing termination entry in the erratum_1386_microcode array in the Linux kernel's x86/CPU/AMD subsystem could cause the x86_match_cpu_with_steppin...

Dec 29, 2024
CVE-2024-56650
7.1

A memory corruption vulnerability in the Linux kernel's netfilter subsystem allows attackers to trigger a slab-out-of-bounds read via specially crafte...

Dec 27, 2024
CVE-2024-56597
7.1

This vulnerability in the Linux kernel's JFS filesystem allows a local attacker to trigger a shift-out-of-bounds error in the dbSplit function when dm...

Dec 27, 2024
CVE-2024-53162
7.1

This CVE-2024-53162 is an off-by-one buffer read vulnerability in the Linux kernel's QAT (QuickAssist Technology) cryptographic driver. It allows atta...

Dec 24, 2024
CVE-2024-53150
7.1

This vulnerability in the Linux kernel's USB audio driver allows out-of-bounds memory reads when processing malicious USB audio device descriptors. At...

Dec 24, 2024
CVE-2024-53147
7.1

This CVE-2024-53147 is an out-of-bounds memory access vulnerability in the Linux kernel's exFAT filesystem driver. It allows attackers with local acce...

Dec 24, 2024
CVE-2024-53108
7.1

This CVE describes an out-of-bounds read vulnerability in the AMD display driver within the Linux kernel. The vulnerability occurs when parsing EDID d...

Dec 2, 2024
CVE-2024-9253
7.1

This vulnerability in Foxit PDF Reader allows remote attackers to read memory beyond allocated buffers when processing malicious PDF files with AcroFo...

Nov 22, 2024
CVE-2024-9246
7.1

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated buffers when processing malicious PDF files with specially cra...

Nov 22, 2024
CVE-2024-9249
7.1

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Nov 22, 2024
CVE-2024-53082
7.1

This CVE addresses an out-of-bounds read/write vulnerability in the Linux kernel's virtio_net driver. The vulnerability occurs when setting or reading...

Nov 19, 2024
CVE-2024-50301
7.1

This is a Linux kernel vulnerability in the key management subsystem that allows an attacker with local access to cause a slab-out-of-bounds read, pot...

Nov 19, 2024
CVE-2024-50278
7.1

A Linux kernel vulnerability in the dm-cache subsystem allows out-of-bounds memory access when resuming a cache table after expanding the underlying f...

Nov 19, 2024
CVE-2024-50123
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's BPF subsystem specifically affecting sockmap link file descriptor informa...

Nov 5, 2024
CVE-2024-50042
7.1

A memory corruption vulnerability in the Linux kernel's Intel Ethernet Controller (ice) driver allows attackers to trigger out-of-bounds memory operat...

Oct 21, 2024
CVE-2022-49031
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's AFE4403 health sensor driver. An attacker with local access can read kern...

Oct 21, 2024
CVE-2022-48966
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's mvneta network driver. An attacker with local access can trigger this vul...

Oct 21, 2024
CVE-2024-49928
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's rtw89 WiFi driver. Attackers could potentially read kernel memory beyond ...

Oct 21, 2024
CVE-2024-47757
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's nilfs2 filesystem driver. The flaw occurs when checking b-tree deletions ...

Oct 21, 2024
CVE-2024-47723
7.1

This vulnerability in the Linux kernel's JFS filesystem allows out-of-bounds memory access when processing corrupted disk images. Attackers could pote...

Oct 21, 2024
CVE-2024-47721
7.1

This vulnerability in the Linux kernel's rtw89 WiFi driver allows out-of-bounds memory access when processing certain firmware events. It affects syst...

Oct 21, 2024
CVE-2024-46764
7.1

A Linux kernel vulnerability in the BPF subsystem allows out-of-bounds read/write due to improper validation of BTF section names. This affects system...

Sep 18, 2024
CVE-2024-46743
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's OpenFirmware interrupt parsing code. When of_irq_parse_raw() is called wi...

Sep 18, 2024
CVE-2024-46731
7.1

This CVE describes an out-of-bounds read vulnerability in the AMD GPU power management driver (drm/amd/pm) in the Linux kernel. An attacker could pote...

Sep 18, 2024
CVE-2024-46722
7.1

This CVE-2024-46722 is an out-of-bounds read vulnerability in the AMD GPU driver within the Linux kernel. It could allow attackers to read kernel memo...

Sep 18, 2024
CVE-2024-46724
7.1

This CVE-2024-46724 is an out-of-bounds read vulnerability in the AMD GPU driver within the Linux kernel. It allows attackers to read kernel memory be...

Sep 18, 2024
CVE-2024-44993
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's V3D GPU driver for Raspberry Pi 5. The vulnerability allows reading beyon...

Sep 4, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,889 CVEs classified as CWE-125, with 203 rated critical and 1,132 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free