CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,906
Total CVEs
207
Critical
1,145
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 301
2 Adobe 175
3 Google 167
4 Apple 113
5 Microsoft 113
6 Debian 100
7 Siemens 63
8 Pdf Xchange 58
9 Fedoraproject 54
10 Samsung 51

All Out-of-bounds Read CVEs (1,906)

CVE-2021-47277
7.1

This CVE describes a speculative execution vulnerability in the Linux kernel's KVM hypervisor where a malicious guest VM could potentially read host k...

May 21, 2024
CVE-2021-47288
7.1

This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's ngene driver, which handles digital TV tuner cards. An attacker c...

May 21, 2024
CVE-2021-47243
7.1

A buffer read vulnerability in the Linux kernel's CAKE (Common Applications Kept Enhanced) queuing discipline allows reading one byte out of bounds wh...

May 21, 2024
CVE-2021-47245
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's netfilter synproxy module when parsing TCP options. Attackers could poten...

May 21, 2024
CVE-2024-35967
7.1

This CVE-2024-35967 is a Linux kernel Bluetooth SCO socket vulnerability where the kernel fails to validate user input length in setsockopt calls, all...

May 20, 2024
CVE-2024-35937
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's WiFi subsystem (cfg80211) when processing A-MSDU frames. Attackers could ...

May 19, 2024
CVE-2024-35896
7.1

This CVE describes a kernel memory corruption vulnerability in the Linux netfilter subsystem where setsockopt() fails to validate user input length be...

May 19, 2024
CVE-2023-52682
7.1

This CVE describes a race condition vulnerability in the Linux kernel's F2FS filesystem where garbage collection (GC) operations can overwrite newly w...

May 17, 2024
CVE-2022-48701
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's USB audio subsystem. When parsing interface descriptors from malicious US...

May 3, 2024
CVE-2023-42090
7.1

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated buffers when processing malicious PDF files containing XFA Doc...

May 3, 2024
CVE-2024-27029
7.1

This CVE describes an out-of-bounds memory access vulnerability in the AMD GPU driver (drm/amdgpu) in the Linux kernel. An attacker could potentially ...

May 1, 2024
CVE-2021-47219
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's scsi_debug driver. An attacker can cause kernel memory corruption by pass...

Apr 10, 2024
CVE-2021-47191
7.1

This is a stack-based buffer overflow vulnerability in the Linux kernel's scsi_debug driver. It allows attackers with local access to cause kernel mem...

Apr 10, 2024
CVE-2024-26789
7.1

This vulnerability in the Linux kernel's ARM64 cryptographic implementation allows out-of-bounds memory access when processing short AES-CTR inputs. I...

Apr 4, 2024
CVE-2024-26791
7.1

This CVE-2024-26791 is an out-of-bounds read vulnerability in the Linux kernel's Btrfs filesystem device replace functionality. Attackers could potent...

Apr 4, 2024
CVE-2024-30335
7.1

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated buffers when processing malicious PDF files with AcroForm anno...

Apr 2, 2024
CVE-2023-52626
7.1

A precedence bug in the Linux kernel's mlx5e network driver causes an out-of-bounds read during port timestamping operations. This vulnerability could...

Mar 26, 2024
CVE-2021-47175
7.1

This is an out-of-bounds memory access vulnerability in the Linux kernel's fq_pie network scheduler. It allows attackers with local access to cause ke...

Mar 25, 2024
CVE-2021-47153
7.1

A vulnerability in the Linux kernel's i2c-i801 driver allows an out-of-bounds memory access when the driver attempts to recover from a timed-out trans...

Mar 25, 2024
CVE-2023-52598
7.1

A race condition vulnerability in the Linux kernel's s390/ptrace interface allows a traced process to corrupt the floating point control (fPC) registe...

Mar 6, 2024
CVE-2021-47097
7.1

This is a stack buffer overflow vulnerability in the Linux kernel's Elantech touchpad driver. Attackers with local access can trigger memory corruptio...

Mar 4, 2024
CVE-2021-47083
7.1

This CVE describes an out-of-bounds memory access vulnerability in the MediaTek pinctrl driver in the Linux kernel. When the virtual external interrup...

Mar 4, 2024
CVE-2023-52519
7.1

A reference count overflow vulnerability in the Linux kernel's Intel ISH HID driver could allow local attackers to cause denial of service or potentia...

Mar 2, 2024
CVE-2023-52565
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's UVC video driver. An attacker with local access can trigger this vulnerab...

Mar 2, 2024
CVE-2023-52501
7.1

A race condition vulnerability in the Linux kernel's ring buffer subsystem allows a malicious process to corrupt kernel memory when reading trace even...

Mar 2, 2024
CVE-2023-52507
7.1

This CVE-2023-52507 is an out-of-bounds read vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem. It allows attackers to pote...

Mar 2, 2024
CVE-2021-47039
7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ataflop driver. An attacker could potentially read kernel memory beyond a...

Feb 28, 2024
CVE-2021-46965
7.1

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's physmap-bt1-rom driver. The bug allows attackers to read kernel ...

Feb 27, 2024
CVE-2021-46952
7.1

This vulnerability in the Linux kernel's NFS implementation allows an attacker to trigger a shift out-of-bounds error by passing a maliciously large '...

Feb 27, 2024
CVE-2021-46954
7.1

This is a stack out-of-bounds read vulnerability in the Linux kernel's network scheduler when fragmenting IPv4 packets. It allows attackers to read ke...

Feb 27, 2024
CVE-2019-25160
7.1

This CVE-2019-25160 is an out-of-bounds memory access vulnerability in the Linux kernel's netlabel subsystem, specifically in cipso_v4_map_lvl_valid()...

Feb 26, 2024
CVE-2024-26597
7.1

A global out-of-bounds read vulnerability in the Linux kernel's RMNET driver allows attackers to read kernel memory beyond allocated bounds when parsi...

Feb 23, 2024
CVE-2024-26594
7.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to send invalid authentication mechanism tokens during session setup, poten...

Feb 23, 2024
CVE-2024-26593
7.1

A vulnerability in the Linux kernel's i2c-i801 driver allows improper memory access during block process call transactions. Attackers could read sensi...

Feb 23, 2024
CVE-2024-23440
7.1

Vba32 Antivirus v3.36.0 contains a driver vulnerability that allows attackers to read arbitrary kernel memory. This affects all systems running the vu...

Feb 13, 2024
CVE-2023-6606
7.1

An out-of-bounds read vulnerability in the Linux kernel's SMB client implementation allows local attackers to read kernel memory. This could lead to s...

Dec 8, 2023
CVE-2023-34044
7.1

This vulnerability allows an attacker with local administrative privileges on a VMware virtual machine to read privileged information from hypervisor ...

Oct 20, 2023
CVE-2023-5377
7.1

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. It affects ...

Oct 4, 2023
CVE-2020-23909
7.1

CVE-2020-23909 is a heap-based buffer over-read vulnerability in the png_convert_4 function of AdvanceMAME's pngex.cc file. This vulnerability allows ...

Jul 18, 2023
CVE-2023-3523
7.1

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. It affects ...

Jul 6, 2023
CVE-2023-32357
7.1

This CVE describes an authorization vulnerability in Apple operating systems where applications can retain access to system configuration files even a...

Jun 23, 2023
CVE-2023-0970
7.1

Multiple buffer overflow vulnerabilities in Silicon Labs Z/IP Gateway SDK versions 7.18.01 and earlier allow attackers with physical access to Z-Wave ...

Jun 21, 2023
CVE-2023-0180
7.1

This vulnerability in NVIDIA GPU Display Driver for Linux allows attackers to exploit a kernel mode layer handler, potentially causing denial of servi...

Apr 1, 2023
CVE-2023-1380
7.1

This CVE describes an out-of-bounds read vulnerability in the Broadcom brcmfmac WiFi driver in the Linux kernel. When processing association request d...

Mar 27, 2023
CVE-2021-32847
7.1

CVE-2021-32847 is an out-of-bounds read vulnerability in HyperKit's virtio block driver that allows a malicious guest VM to read host memory. This can...

Feb 20, 2023
CVE-2022-35234
7.1

Trend Micro Security 2021 and 2022 (Consumer) contains an out-of-bounds read vulnerability that could allow an attacker to read sensitive information ...

Jul 30, 2022
CVE-2022-26697
7.1

This vulnerability allows attackers to read memory outside intended boundaries when processing malicious AppleScript binary files. It affects macOS Ca...

May 26, 2022
CVE-2022-30976
7.1

CVE-2022-30976 is a heap-based buffer over-read vulnerability in GPAC's Unicode handling function. Attackers can exploit this by crafting malicious MP...

May 18, 2022
CVE-2022-1714
7.1

CVE-2022-1714 is an out-of-bounds read vulnerability in radare2 reverse engineering framework versions prior to 5.7.0. This allows attackers to read s...

May 13, 2022
CVE-2022-29458
7.1

CVE-2022-29458 is an out-of-bounds read vulnerability in ncurses' terminfo library that can cause segmentation faults and potentially lead to informat...

Apr 18, 2022

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,906 CVEs classified as CWE-125, with 207 rated critical and 1,145 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free