CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,912
Total CVEs
207
Critical
1,151
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 302
2 Adobe 175
3 Google 167
4 Apple 113
5 Microsoft 113
6 Debian 101
7 Siemens 64
8 Pdf Xchange 58
9 Fedoraproject 56
10 Samsung 51

All Out-of-bounds Read CVEs (1,912)

CVE-2021-32847
7.1

CVE-2021-32847 is an out-of-bounds read vulnerability in HyperKit's virtio block driver that allows a malicious guest VM to read host memory. This can...

Feb 20, 2023
CVE-2022-35234
7.1

Trend Micro Security 2021 and 2022 (Consumer) contains an out-of-bounds read vulnerability that could allow an attacker to read sensitive information ...

Jul 30, 2022
CVE-2022-26697
7.1

This vulnerability allows attackers to read memory outside intended boundaries when processing malicious AppleScript binary files. It affects macOS Ca...

May 26, 2022
CVE-2022-30976
7.1

CVE-2022-30976 is a heap-based buffer over-read vulnerability in GPAC's Unicode handling function. Attackers can exploit this by crafting malicious MP...

May 18, 2022
CVE-2022-1714
7.1

CVE-2022-1714 is an out-of-bounds read vulnerability in radare2 reverse engineering framework versions prior to 5.7.0. This allows attackers to read s...

May 13, 2022
CVE-2022-29458
7.1

CVE-2022-29458 is an out-of-bounds read vulnerability in ncurses' terminfo library that can cause segmentation faults and potentially lead to informat...

Apr 18, 2022
CVE-2022-27523
7.1

A buffer over-read vulnerability in Autodesk TrueView 2022 allows attackers to expose sensitive information or cause application crashes by tricking u...

Apr 13, 2022
CVE-2021-4156
7.1

An out-of-bounds read vulnerability in libsndfile's FLAC codec allows attackers to crash applications or potentially leak memory information by submit...

Mar 23, 2022
CVE-2022-22627
7.1

This vulnerability allows attackers to cause AppleScript binaries to read memory outside intended bounds, potentially leading to application crashes o...

Mar 18, 2022
CVE-2022-22625
7.1

This vulnerability allows attackers to read memory outside intended boundaries when processing malicious AppleScript binaries. It affects macOS Catali...

Mar 18, 2022
CVE-2022-0630
7.1

CVE-2022-0630 is an out-of-bounds read vulnerability in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to read memory b...

Feb 19, 2022
CVE-2022-21711
7.1

CVE-2022-21711 is an out-of-bounds read vulnerability in elfspirit versions prior to 1.1 that allows attackers to cause application crashes or leak me...

Jan 24, 2022
CVE-2021-4166
7.1

CVE-2021-4166 is an out-of-bounds read vulnerability in Vim text editor that allows attackers to read memory contents beyond allocated buffers. This a...

Dec 25, 2021
CVE-2021-29328
7.1

CVE-2021-29328 is a buffer over-read vulnerability in Moddable's fxDebugThrow function that could allow attackers to read sensitive memory contents. T...

Nov 19, 2021
CVE-2021-31881
7.1

This vulnerability in Siemens Capital Embedded AR Classic products allows attackers to cause denial-of-service conditions by sending specially crafted...

Nov 9, 2021
CVE-2021-41224
7.1

This vulnerability in TensorFlow allows attackers to trigger a heap out-of-bounds memory access by providing mismatched sizes for indices and values a...

Nov 5, 2021
CVE-2021-41205
7.1

This CVE describes an out-of-bounds read vulnerability in TensorFlow's QuantizeAndDequantizeV* operations that could allow attackers to read sensitive...

Nov 5, 2021
CVE-2021-41212
7.1

This vulnerability in TensorFlow allows attackers to trigger an out-of-bounds read in the tf.ragged.cross function, potentially leading to memory disc...

Nov 5, 2021
CVE-2021-22469
7.1

CVE-2021-22469 is an out-of-bounds read vulnerability in HarmonyOS kernel components that allows local attackers to read kernel memory beyond allocate...

Oct 28, 2021
CVE-2021-30719
7.1

This macOS vulnerability allows local users to read kernel memory or cause system crashes through an out-of-bounds read. It affects macOS systems prio...

Sep 8, 2021
CVE-2021-30879
7.1

This vulnerability allows attackers to read memory outside intended boundaries when processing malicious AppleScript binary files. It affects macOS sy...

Aug 24, 2021
CVE-2021-30876
7.1

CVE-2021-30876 is an out-of-bounds read vulnerability in AppleScript binary processing on macOS. Attackers can craft malicious AppleScript binaries to...

Aug 24, 2021
CVE-2021-35940
7.1

CVE-2021-35940 is an out-of-bounds read vulnerability in Apache Portable Runtime (APR) 1.7.x branch that allows reading memory beyond allocated array ...

Aug 23, 2021
CVE-2021-25802
7.1

A buffer overflow vulnerability in VLC Media Player's subtitle parsing component allows attackers to trigger out-of-bounds memory reads via specially ...

Jul 26, 2021
CVE-2019-25048
7.1

This vulnerability in LibreSSL allows attackers to read beyond allocated heap memory boundaries when processing ASN.1 data structures. It affects syst...

Jul 1, 2021
CVE-2021-29964
7.1

This vulnerability allows a malicious program already running on a Windows system to send specially crafted WM_COPYDATA messages to Firefox, causing a...

Jun 24, 2021
CVE-2021-32950
7.1

This vulnerability allows attackers to cause denial-of-service or read sensitive memory information by exploiting an out-of-bounds read issue in the D...

Jun 17, 2021
CVE-2021-32938
7.1

This vulnerability in Drawings SDK allows attackers to read sensitive information from memory or cause denial-of-service by exploiting improper valida...

Jun 17, 2021
CVE-2020-11161
7.1

This vulnerability allows out-of-bounds memory access in Qualcomm Snapdragon chipsets when processing negative width values from external components. ...

Jun 9, 2021
CVE-2021-32614
7.1

This is an out-of-bounds read vulnerability in dmg2img versions through 20170502. An attacker can trigger a buffer overflow by providing a specially c...

May 26, 2021
CVE-2021-3548
7.1

CVE-2021-3548 is a buffer overflow vulnerability in dmg2img versions through 20170502 where improper validation of read buffer size during memcpy() ca...

May 26, 2021
CVE-2020-24119
7.1

CVE-2020-24119 is a heap buffer overflow vulnerability in UPX 4.0.0's ELF file parser that allows reading beyond allocated memory boundaries. This aff...

May 14, 2021
CVE-2020-23921
7.1

CVE-2020-23921 is a heap-based buffer over-read vulnerability in fast_ber's ASN.1 compiler. This allows attackers to read memory beyond allocated buff...

Apr 21, 2021
CVE-2020-23928
7.1

CVE-2020-23928 is a heap-based buffer over-read vulnerability in GPAC's abst_box_read function that allows reading beyond allocated memory boundaries....

Apr 21, 2021
CVE-2020-23931
7.1

CVE-2020-23931 is a heap-based buffer over-read vulnerability in GPAC's abst_box_read function that allows reading beyond allocated memory boundaries....

Apr 21, 2021
CVE-2020-27936
7.1

CVE-2020-27936 is an out-of-bounds read vulnerability in macOS kernel memory that allows local users to read kernel memory or cause system crashes. Th...

Apr 2, 2021
CVE-2021-21072
7.1

CVE-2021-21072 is an out-of-bounds read vulnerability in Adobe Animate that allows an attacker to read sensitive memory contents. Users who open malic...

Mar 12, 2021
CVE-2021-21074
7.1

Adobe Animate versions 21.0.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive information from ...

Mar 12, 2021
CVE-2021-21076
7.1

Adobe Animate versions 21.0.3 and earlier contain an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory contents. ...

Mar 12, 2021
CVE-2021-27364
7.1

CVE-2021-27364 is a Linux kernel vulnerability in the iSCSI subsystem that allows unprivileged local users to cause a denial of service or potentially...

Mar 7, 2021
CVE-2021-26926
7.1

CVE-2021-26926 is an out-of-bounds read vulnerability in Jasper's jp2_decode function that could allow attackers to read sensitive memory contents or ...

Feb 23, 2021
CVE-2021-22302
7.1

This is an out-of-bounds read vulnerability in certain Huawei smartphones where a module fails to properly validate input. Attackers can exploit this ...

Feb 6, 2021
CVE-2020-35653
7.1

This vulnerability in Pillow's PCX file decoder allows attackers to read beyond allocated memory buffers when processing malicious PCX files. It affec...

Jan 12, 2021
CVE-2020-9779
7.1

CVE-2020-9779 is an out-of-bounds read vulnerability in macOS kernel memory handling that allows a local user to read kernel memory or cause system cr...

Oct 22, 2020
CVE-2020-14377
7.1

This vulnerability in DPDK allows an attacker in a virtual machine to read significant amounts of host memory due to a buffer over-read. The flaw exis...

Sep 30, 2020
CVE-2020-24344
7.1

CVE-2020-24344 is a buffer over-read vulnerability in JerryScript's JavaScript engine affecting versions through 2.3.0. This allows reading memory bey...

Aug 13, 2020
CVE-2020-13902
7.1

This vulnerability in ImageMagick allows attackers to read heap memory beyond allocated buffers when processing specially crafted TIFF images. It affe...

Jun 7, 2020
CVE-2019-14042
7.1

This vulnerability allows an attacker to read memory outside the intended buffer in the fingerprint application on Qualcomm Snapdragon chipsets. It af...

Jun 2, 2020
CVE-2020-1806
7.1

This vulnerability affects Huawei Honor V10 smartphones where certain driver programs fail to properly validate parameters, leading to out-of-bounds r...

Apr 27, 2020
CVE-2020-1804
7.1

This vulnerability in Huawei Honor V10 smartphones allows out-of-bounds read in a driver program due to insufficient parameter validation. Successful ...

Apr 27, 2020

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,912 CVEs classified as CWE-125, with 207 rated critical and 1,151 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free