CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,900
Total CVEs
205
Critical
1,141
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 301
2 Adobe 175
3 Google 167
4 Apple 113
5 Microsoft 113
6 Debian 99
7 Siemens 63
8 Pdf Xchange 58
9 Fedoraproject 53
10 Samsung 51

All Out-of-bounds Read CVEs (1,900)

CVE-2024-49928
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's rtw89 WiFi driver. Attackers could potentially read kernel memory beyond ...

Oct 21, 2024
CVE-2024-47757
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's nilfs2 filesystem driver. The flaw occurs when checking b-tree deletions ...

Oct 21, 2024
CVE-2024-47723
7.1

This vulnerability in the Linux kernel's JFS filesystem allows out-of-bounds memory access when processing corrupted disk images. Attackers could pote...

Oct 21, 2024
CVE-2024-47721
7.1

This vulnerability in the Linux kernel's rtw89 WiFi driver allows out-of-bounds memory access when processing certain firmware events. It affects syst...

Oct 21, 2024
CVE-2024-46764
7.1

A Linux kernel vulnerability in the BPF subsystem allows out-of-bounds read/write due to improper validation of BTF section names. This affects system...

Sep 18, 2024
CVE-2024-46743
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's OpenFirmware interrupt parsing code. When of_irq_parse_raw() is called wi...

Sep 18, 2024
CVE-2024-46731
7.1

This CVE describes an out-of-bounds read vulnerability in the AMD GPU power management driver (drm/amd/pm) in the Linux kernel. An attacker could pote...

Sep 18, 2024
CVE-2024-46722
7.1

This CVE-2024-46722 is an out-of-bounds read vulnerability in the AMD GPU driver within the Linux kernel. It could allow attackers to read kernel memo...

Sep 18, 2024
CVE-2024-46724
7.1

This CVE-2024-46724 is an out-of-bounds read vulnerability in the AMD GPU driver within the Linux kernel. It allows attackers to read kernel memory be...

Sep 18, 2024
CVE-2024-44993
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's V3D GPU driver for Raspberry Pi 5. The vulnerability allows reading beyon...

Sep 4, 2024
CVE-2024-43877
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's IVTV media driver. When DMA mapping fails, the driver attempts t...

Aug 21, 2024
CVE-2024-42292
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's kobject_uevent subsystem. The flaw occurs when zap_modalias_env(...

Aug 17, 2024
CVE-2024-42264
7.1

This CVE-2024-42264 is an out-of-bounds memory access vulnerability in the Linux kernel's DRM/V3D graphics driver. It allows attackers to read kernel ...

Aug 17, 2024
CVE-2024-40799
7.1

An out-of-bounds read vulnerability in Apple operating systems allows processing malicious files to cause unexpected application termination. This aff...

Jul 29, 2024
CVE-2024-41090
7.1

A vulnerability in the Linux kernel's TAP device driver allows short Ethernet frames (shorter than the Ethernet header size) to be processed incorrect...

Jul 29, 2024
CVE-2024-41013
7.1

This CVE-2024-41013 is an out-of-bounds read vulnerability in the XFS filesystem implementation in the Linux kernel. Attackers can exploit this by cra...

Jul 29, 2024
CVE-2022-48866
7.1

This vulnerability allows an attacker to trigger an out-of-bounds read in the Linux kernel's HID thrustmaster driver when a malicious USB device is co...

Jul 16, 2024
CVE-2022-48827
7.1

A Linux kernel NFS server vulnerability where reading files near the maximum offset (OFFSET_MAX) causes an integer overflow, returning an invalid erro...

Jul 16, 2024
CVE-2024-40978
7.1

This CVE describes a kernel crash vulnerability in the Linux kernel's QLogic QEDI iSCSI driver. The vulnerability occurs when reading debugfs attribut...

Jul 12, 2024
CVE-2024-40929
7.1

This CVE describes an out-of-bounds read vulnerability in the iwlwifi driver in the Linux kernel. Attackers could potentially read kernel memory conte...

Jul 12, 2024
CVE-2024-39467
7.1

A memory corruption vulnerability in the Linux kernel's F2FS filesystem allows attackers to trigger out-of-bounds reads via specially crafted filesyst...

Jun 25, 2024
CVE-2024-39471
7.1

This CVE addresses an out-of-bounds read vulnerability in the AMD GPU driver (drm/amdgpu) in the Linux kernel. When the sdma_v4_0_irq_id_to_seq functi...

Jun 25, 2024
CVE-2024-34777
7.1

A memory corruption vulnerability in the Linux kernel's DMA mapping benchmark module allows local attackers to trigger a wild memory access via invali...

Jun 21, 2024
CVE-2024-38635
7.1

A memory corruption vulnerability in the Linux kernel's SoundWire Cadence driver allows out-of-bounds memory access due to incorrect PDI offset calcul...

Jun 21, 2024
CVE-2022-48738
7.1

This CVE is an out-of-bounds write vulnerability in the Linux kernel's ALSA sound subsystem. It allows attackers to write values outside the valid ran...

Jun 20, 2024
CVE-2022-48714
7.1

This CVE is a memory access vulnerability in the Linux kernel's BPF ring buffer implementation where incorrect virtual memory flags allow KASAN (Kerne...

Jun 20, 2024
CVE-2021-47604
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's vduse driver. An attacker could read kernel memory beyond allocated bound...

Jun 19, 2024
CVE-2024-38572
7.1

This vulnerability in the Linux kernel's ath12k WiFi driver allows out-of-bounds memory access when processing QMI messages, potentially leading to ke...

Jun 19, 2024
CVE-2024-38560
7.1

This CVE describes a buffer overflow vulnerability in the Linux kernel's bfa SCSI driver. An attacker could exploit this to read kernel memory beyond ...

Jun 19, 2024
CVE-2022-48578
7.1

An out-of-bounds read vulnerability in AppleScript processing on macOS Monterey allows attackers to cause unexpected termination or memory disclosure....

Jun 10, 2024
CVE-2024-36960
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's VMware graphics driver (vmwgfx). The flaw occurs when the kernel incorrec...

Jun 3, 2024
CVE-2024-36931
7.1

This CVE-2024-36931 is a Linux kernel vulnerability in the s390/cio subsystem where a buffer copied from userspace is not properly NUL-terminated, all...

May 30, 2024
CVE-2024-36916
7.1

This CVE-2024-36916 is a Linux kernel vulnerability in the blk-iocost subsystem where an out-of-bounds shift operation can cause undefined behavior. I...

May 30, 2024
CVE-2024-36883
7.1

This is a Linux kernel race condition vulnerability in network subsystem initialization that allows out-of-bounds memory access. It affects Linux syst...

May 30, 2024
CVE-2024-36019
7.1

This vulnerability is an out-of-bounds memory access bug in the Linux kernel's regmap maple cache subsystem that can corrupt kernel memory. It affects...

May 30, 2024
CVE-2023-52866
7.1

A null pointer dereference vulnerability in the Linux kernel's HID uclogic driver allows local attackers to cause a kernel panic (denial of service) o...

May 21, 2024
CVE-2023-52827
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ath12k WiFi driver. An attacker could potentially read kernel memory beyo...

May 21, 2024
CVE-2023-52794
7.1

This CVE describes a kernel memory corruption vulnerability in the Linux kernel's Intel PowerClamp thermal driver. A type mismatch in the max_idle par...

May 21, 2024
CVE-2021-47390
7.1

This CVE describes a stack-based buffer overflow vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem. The flaw occurs whe...

May 21, 2024
CVE-2021-47393
7.1

A kernel memory corruption vulnerability in the Linux kernel's mlxreg-fan driver allows local attackers to trigger an out-of-bounds read when enforcin...

May 21, 2024
CVE-2021-47383
7.1

A memory corruption vulnerability in the Linux kernel's framebuffer console driver allows local attackers to trigger out-of-bounds memory access via a...

May 21, 2024
CVE-2021-47346
7.1

This is a global-out-of-bounds read vulnerability in the Linux kernel's CoreSight TMC-ETF driver. It allows reading kernel memory beyond allocated bou...

May 21, 2024
CVE-2021-47309
7.1

A Linux kernel vulnerability in the skb_tunnel_info() function allows reading kernel memory beyond allocated bounds when processing certain network pa...

May 21, 2024
CVE-2021-47291
7.1

This is a memory corruption vulnerability in the Linux kernel's IPv6 routing subsystem that can cause slab-out-of-bounds reads/writes. It affects Linu...

May 21, 2024
CVE-2021-47277
7.1

This CVE describes a speculative execution vulnerability in the Linux kernel's KVM hypervisor where a malicious guest VM could potentially read host k...

May 21, 2024
CVE-2021-47288
7.1

This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's ngene driver, which handles digital TV tuner cards. An attacker c...

May 21, 2024
CVE-2021-47243
7.1

A buffer read vulnerability in the Linux kernel's CAKE (Common Applications Kept Enhanced) queuing discipline allows reading one byte out of bounds wh...

May 21, 2024
CVE-2021-47245
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's netfilter synproxy module when parsing TCP options. Attackers could poten...

May 21, 2024
CVE-2024-35967
7.1

This CVE-2024-35967 is a Linux kernel Bluetooth SCO socket vulnerability where the kernel fails to validate user input length in setsockopt calls, all...

May 20, 2024
CVE-2024-35937
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's WiFi subsystem (cfg80211) when processing A-MSDU frames. Attackers could ...

May 19, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,900 CVEs classified as CWE-125, with 205 rated critical and 1,141 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free