CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,923)
CVE-2021-26926 is an out-of-bounds read vulnerability in Jasper's jp2_decode function that could allow attackers to read sensitive memory contents or ...
Feb 23, 2021This is an out-of-bounds read vulnerability in certain Huawei smartphones where a module fails to properly validate input. Attackers can exploit this ...
Feb 6, 2021This vulnerability in Pillow's PCX file decoder allows attackers to read beyond allocated memory buffers when processing malicious PCX files. It affec...
Jan 12, 2021CVE-2020-9779 is an out-of-bounds read vulnerability in macOS kernel memory handling that allows a local user to read kernel memory or cause system cr...
Oct 22, 2020This vulnerability in DPDK allows an attacker in a virtual machine to read significant amounts of host memory due to a buffer over-read. The flaw exis...
Sep 30, 2020CVE-2020-24344 is a buffer over-read vulnerability in JerryScript's JavaScript engine affecting versions through 2.3.0. This allows reading memory bey...
Aug 13, 2020This vulnerability in ImageMagick allows attackers to read heap memory beyond allocated buffers when processing specially crafted TIFF images. It affe...
Jun 7, 2020This vulnerability allows an attacker to read memory outside the intended buffer in the fingerprint application on Qualcomm Snapdragon chipsets. It af...
Jun 2, 2020This vulnerability affects Huawei Honor V10 smartphones where certain driver programs fail to properly validate parameters, leading to out-of-bounds r...
Apr 27, 2020This vulnerability in Huawei Honor V10 smartphones allows out-of-bounds read in a driver program due to insufficient parameter validation. Successful ...
Apr 27, 2020This vulnerability allows out-of-bounds memory access in Qualcomm Snapdragon chipsets due to missing null pointer checks. Attackers could potentially ...
Apr 16, 2020CVE-2020-3908 is an out-of-bounds read vulnerability in macOS kernel memory handling that allows local users to cause system crashes or read kernel me...
Apr 1, 2020This CVE describes a buffer over-read vulnerability in Qualcomm's WLAN module when processing SAR limits messages with invalid parameters. It affects ...
Mar 5, 2020This vulnerability in the Linux kernel's floppy driver allows an out-of-bounds read when accessing the Floppy Disk Controller (FDC) index without prop...
Feb 25, 2020CVE-2020-6624 is a heap-based buffer over-read vulnerability in jhead's process_DQT function that could allow attackers to read sensitive memory conte...
Jan 9, 2020This vulnerability is a buffer overflow in the FLI image decoder component of Pillow (Python Imaging Library). Attackers can exploit this by crafting ...
Jan 3, 2020CVE-2019-8576 is an out-of-bounds read vulnerability in Apple operating systems that allows a local user to read kernel memory or cause system crashes...
Dec 18, 2019This vulnerability allows an authorized attacker to perform an out-of-bounds read in Windows Desktop Window Manager (DWM), potentially leading to loca...
Oct 14, 2025CVE-2025-2784 is a heap buffer over-read vulnerability in libsoup's skip_insight_whitespace() function. When processing a malicious HTTP response, lib...
Apr 3, 2025This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with elevated SYSTEM privileges. ...
Dec 12, 2024This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with elevated SYSTEM privileges. ...
Dec 12, 2024This vulnerability in the Windows Mobile Broadband Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploit...
Dec 12, 2024This CVE describes an elevation of privilege vulnerability in the Windows Mobile Broadband Driver. It allows an authenticated attacker to gain SYSTEM-...
Dec 12, 2024A heap overflow vulnerability in QEMU's virtio-net device allows privileged guest users to crash the host QEMU process by manipulating RSS indirection...
Jul 5, 2024This vulnerability allows a malicious actor with local administrative privileges on a virtual machine with an existing snapshot to trigger an out-of-b...
Jun 25, 2024This CVE describes an out-of-bounds read vulnerability in the DMA module's register configuration. Successful exploitation could allow attackers to re...
Aug 6, 2025This vulnerability in PlayReady TA allows an attacker with System privilege to perform an out-of-bounds read, potentially leading to local privilege e...
Apr 7, 2025This CVE describes an out-of-bounds read vulnerability in Android's SIM data parsing component that could allow local privilege escalation. Attackers ...
Mar 24, 2023This CVE describes an out-of-bounds read vulnerability in a Huawei driver module that could allow attackers to access invalid memory. Successful explo...
Nov 28, 2025This vulnerability in GStreamer's isomp4 plugin allows attackers to read beyond allocated heap buffer boundaries when parsing malicious MP4 files. Thi...
Aug 7, 2025This CVE describes an out-of-bounds array access vulnerability in the kernel ambient light module due to insufficient data verification. Successful ex...
Aug 6, 2025This CVE describes an out-of-bounds array access vulnerability in the kernel ambient light module due to insufficient data verification. Successful ex...
Aug 6, 2025This vulnerability allows an authorized attacker with physical access to a Windows system to exploit an out-of-bounds read in the USB Video Driver, po...
Mar 11, 2025This vulnerability allows arbitrary reads from Trusted Execution Environment (TEE) memory due to a logic error in the ppcfw_deny_sec_dram_access funct...
Mar 10, 2025This Windows Digital Media vulnerability allows attackers to elevate privileges on affected systems by exploiting an out-of-bounds read weakness. It a...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows Digital Media vulnerability allows attackers to gain elevated privileges on affected systems by exploiting an out-of-bounds read weakness...
Jan 14, 2025This Windows vulnerability allows attackers to gain elevated privileges on affected systems by exploiting improper bounds checking in Digital Media co...
Jan 14, 2025This Windows Digital Media Elevation of Privilege vulnerability (CWE-125: Out-of-bounds Read) allows authenticated attackers to gain SYSTEM-level priv...
Jan 14, 2025This vulnerability in Ruby's regex compiler allows attackers to read arbitrary heap memory when processing malicious regex patterns. This can leak sen...
May 14, 2024An out-of-bounds read vulnerability in QNAP File Station 5 allows authenticated remote attackers to read sensitive memory contents. This affects users...
Feb 11, 2026This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...
Feb 2, 2026This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...
Feb 2, 2026An out-of-bounds read vulnerability in TeamViewer DEX Client's Content Distribution Service allows remote attackers to leak stack memory and cause den...
Jan 29, 2026A segmentation violation vulnerability in OneFlow's logical_or component allows attackers to crash the application via specially crafted input, causin...
Jan 28, 2026A segmentation violation vulnerability in OneFlow's flow.column_stack component allows attackers to cause Denial of Service (DoS) through crafted inpu...
Jan 28, 2026About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,923 CVEs classified as CWE-125, with 209 rated critical and 1,160 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free