CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,923
Total CVEs
209
Critical
1,160
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 302
2 Adobe 179
3 Google 167
4 Apple 117
5 Microsoft 113
6 Debian 102
7 Siemens 64
8 Pdf Xchange 58
9 Fedoraproject 56
10 Samsung 51

All Out-of-bounds Read CVEs (1,923)

CVE-2021-26926
7.1

CVE-2021-26926 is an out-of-bounds read vulnerability in Jasper's jp2_decode function that could allow attackers to read sensitive memory contents or ...

Feb 23, 2021
CVE-2021-22302
7.1

This is an out-of-bounds read vulnerability in certain Huawei smartphones where a module fails to properly validate input. Attackers can exploit this ...

Feb 6, 2021
CVE-2020-35653
7.1

This vulnerability in Pillow's PCX file decoder allows attackers to read beyond allocated memory buffers when processing malicious PCX files. It affec...

Jan 12, 2021
CVE-2020-9779
7.1

CVE-2020-9779 is an out-of-bounds read vulnerability in macOS kernel memory handling that allows a local user to read kernel memory or cause system cr...

Oct 22, 2020
CVE-2020-14377
7.1

This vulnerability in DPDK allows an attacker in a virtual machine to read significant amounts of host memory due to a buffer over-read. The flaw exis...

Sep 30, 2020
CVE-2020-24344
7.1

CVE-2020-24344 is a buffer over-read vulnerability in JerryScript's JavaScript engine affecting versions through 2.3.0. This allows reading memory bey...

Aug 13, 2020
CVE-2020-13902
7.1

This vulnerability in ImageMagick allows attackers to read heap memory beyond allocated buffers when processing specially crafted TIFF images. It affe...

Jun 7, 2020
CVE-2019-14042
7.1

This vulnerability allows an attacker to read memory outside the intended buffer in the fingerprint application on Qualcomm Snapdragon chipsets. It af...

Jun 2, 2020
CVE-2020-1806
7.1

This vulnerability affects Huawei Honor V10 smartphones where certain driver programs fail to properly validate parameters, leading to out-of-bounds r...

Apr 27, 2020
CVE-2020-1804
7.1

This vulnerability in Huawei Honor V10 smartphones allows out-of-bounds read in a driver program due to insufficient parameter validation. Successful ...

Apr 27, 2020
CVE-2019-14104
7.1

This vulnerability allows out-of-bounds memory access in Qualcomm Snapdragon chipsets due to missing null pointer checks. Attackers could potentially ...

Apr 16, 2020
CVE-2020-3908
7.1

CVE-2020-3908 is an out-of-bounds read vulnerability in macOS kernel memory handling that allows local users to cause system crashes or read kernel me...

Apr 1, 2020
CVE-2019-14081
7.1

This CVE describes a buffer over-read vulnerability in Qualcomm's WLAN module when processing SAR limits messages with invalid parameters. It affects ...

Mar 5, 2020
CVE-2020-9383
7.1

This vulnerability in the Linux kernel's floppy driver allows an out-of-bounds read when accessing the Floppy Disk Controller (FDC) index without prop...

Feb 25, 2020
CVE-2020-6624
7.1

CVE-2020-6624 is a heap-based buffer over-read vulnerability in jhead's process_DQT function that could allow attackers to read sensitive memory conte...

Jan 9, 2020
CVE-2020-5313
7.1

This vulnerability is a buffer overflow in the FLI image decoder component of Pillow (Python Imaging Library). Attackers can exploit this by crafting ...

Jan 3, 2020
CVE-2019-8576
7.1

CVE-2019-8576 is an out-of-bounds read vulnerability in Apple operating systems that allows a local user to read kernel memory or cause system crashes...

Dec 18, 2019
CVE-2025-55681
7.0

This vulnerability allows an authorized attacker to perform an out-of-bounds read in Windows Desktop Window Manager (DWM), potentially leading to loca...

Oct 14, 2025
CVE-2025-2784
7.0

CVE-2025-2784 is a heap buffer over-read vulnerability in libsoup's skip_insight_whitespace() function. When processing a malicious HTTP response, lib...

Apr 3, 2025
CVE-2024-49110
6.8

This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with elevated SYSTEM privileges. ...

Dec 12, 2024
CVE-2024-49092
6.8

This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with elevated SYSTEM privileges. ...

Dec 12, 2024
CVE-2024-49078
6.8

This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploit...

Dec 12, 2024
CVE-2024-49083
6.8

This CVE describes an elevation of privilege vulnerability in the Windows Mobile Broadband Driver. It allows an authenticated attacker to gain SYSTEM-...

Dec 12, 2024
CVE-2024-6505
6.8

A heap overflow vulnerability in QEMU's virtio-net device allows privileged guest users to crash the host QEMU process by manipulating RSS indirection...

Jul 5, 2024
CVE-2024-37086
6.8

This vulnerability allows a malicious actor with local administrative privileges on a virtual machine with an existing snapshot to trigger an out-of-b...

Jun 25, 2024
CVE-2025-54633
6.7

This CVE describes an out-of-bounds read vulnerability in the DMA module's register configuration. Successful exploitation could allow attackers to re...

Aug 6, 2025
CVE-2025-20661
6.7

This vulnerability in PlayReady TA allows an attacker with System privilege to perform an out-of-bounds read, potentially leading to local privilege e...

Apr 7, 2025
CVE-2023-21063
6.7

This CVE describes an out-of-bounds read vulnerability in Android's SIM data parsing component that could allow local privilege escalation. Attackers ...

Mar 24, 2023
CVE-2025-58314
6.6

This CVE describes an out-of-bounds read vulnerability in a Huawei driver module that could allow attackers to access invalid memory. Successful explo...

Nov 28, 2025
CVE-2025-47183
6.6

This vulnerability in GStreamer's isomp4 plugin allows attackers to read beyond allocated heap buffer boundaries when parsing malicious MP4 files. Thi...

Aug 7, 2025
CVE-2025-54643
6.6

This CVE describes an out-of-bounds array access vulnerability in the kernel ambient light module due to insufficient data verification. Successful ex...

Aug 6, 2025
CVE-2025-54644
6.6

This CVE describes an out-of-bounds array access vulnerability in the kernel ambient light module due to insufficient data verification. Successful ex...

Aug 6, 2025
CVE-2025-24988
6.6

This vulnerability allows an authorized attacker with physical access to a Windows system to exploit an out-of-bounds read in the USB Video Driver, po...

Mar 11, 2025
CVE-2024-56187
6.6

This vulnerability allows arbitrary reads from Trusted Execution Environment (TEE) memory due to a logic error in the ppcfw_deny_sec_dram_access funct...

Mar 10, 2025
CVE-2025-21327
6.6

This Windows Digital Media vulnerability allows attackers to elevate privileges on affected systems by exploiting an out-of-bounds read weakness. It a...

Jan 14, 2025
CVE-2025-21310
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21263
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21260
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21255
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21249
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21229
6.6

This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...

Jan 14, 2025
CVE-2025-21232
6.6

This Windows vulnerability allows attackers to gain elevated privileges on affected systems by exploiting improper bounds checking in Digital Media co...

Jan 14, 2025
CVE-2025-21227
6.6

This Windows Digital Media Elevation of Privilege vulnerability (CWE-125: Out-of-bounds Read) allows authenticated attackers to gain SYSTEM-level priv...

Jan 14, 2025
CVE-2024-27282
6.6

This vulnerability in Ruby's regex compiler allows attackers to read arbitrary heap memory when processing malicious regex patterns. This can leak sen...

May 14, 2024
CVE-2025-54169
6.5

An out-of-bounds read vulnerability in QNAP File Station 5 allows authenticated remote attackers to read sensitive memory contents. This affects users...

Feb 11, 2026
CVE-2026-20420
6.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2, 2026
CVE-2026-20421
6.5

This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...

Feb 2, 2026
CVE-2026-23569
6.5

An out-of-bounds read vulnerability in TeamViewer DEX Client's Content Distribution Service allows remote attackers to leak stack memory and cause den...

Jan 29, 2026
CVE-2025-71004
6.5

A segmentation violation vulnerability in OneFlow's logical_or component allows attackers to crash the application via specially crafted input, causin...

Jan 28, 2026
CVE-2025-71001
6.5

A segmentation violation vulnerability in OneFlow's flow.column_stack component allows attackers to cause Denial of Service (DoS) through crafted inpu...

Jan 28, 2026

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,923 CVEs classified as CWE-125, with 209 rated critical and 1,160 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free