CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,927)
This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...
Feb 2, 2026An out-of-bounds read vulnerability in TeamViewer DEX Client's Content Distribution Service allows remote attackers to leak stack memory and cause den...
Jan 29, 2026A segmentation violation vulnerability in OneFlow's logical_or component allows attackers to crash the application via specially crafted input, causin...
Jan 28, 2026A segmentation violation vulnerability in OneFlow's flow.column_stack component allows attackers to cause Denial of Service (DoS) through crafted inpu...
Jan 28, 2026This vulnerability allows authenticated attackers to read arbitrary files from the server filesystem in Area9 Rhapsode 1.47.3 by exploiting operation,...
Jan 9, 2026An out-of-bounds read vulnerability in QNAP License Center allows authenticated remote attackers to read sensitive memory contents. This affects users...
Jan 2, 2026CVE-2025-68431 is a heap buffer over-read vulnerability in libheif's overlay image processing. Attackers can craft malicious HEIF files to trigger mem...
Dec 29, 2025An out-of-bounds read vulnerability in the NFS protocol dissector allows unauthenticated remote attackers to cause a denial-of-service via process cra...
Dec 18, 2025A memory disclosure vulnerability in libcoap's OSCORE configuration parser allows attackers to read memory beyond string boundaries in the .rodata sec...
Dec 8, 2025An out-of-bounds read vulnerability in PDF-XChange Editor's EMF functionality allows attackers to read memory beyond intended boundaries via specially...
Dec 2, 2025FeehiCMS version 2.1.1 has a server-side validation flaw where parameters marked as read-only on the client side can be modified by authenticated atta...
Dec 1, 2025AstrBot Project v3.5.22 contains an arbitrary file read vulnerability in the _encode_image_bs64 function that allows attackers to read any file on the...
Nov 7, 2025A floating-point precision error in QuickJS's TypedArray.prototype.indexOf() allows out-of-bounds memory read when using extremely small negative from...
Oct 16, 2025This vulnerability in QuickJS engine allows attackers to read memory beyond allocated BigInt buffers during string conversion, potentially exposing se...
Oct 16, 2025This vulnerability in NetX Duo's _nx_ip_packet_receive() function allows an attacker to cause an out-of-bounds read by sending specially crafted Ether...
Oct 16, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read memory contents over the...
Oct 14, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read memory contents they sho...
Oct 14, 2025This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Windows Routing and Remote Access Service (RRAS), pot...
Sep 9, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...
Sep 9, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...
Sep 9, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...
Sep 9, 2025This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth SDP discovery component that could allow remote attackers to read sensit...
Sep 4, 2025This vulnerability allows authenticated remote attackers to read memory beyond intended boundaries in SAEMM_RadioMessageCodec.c, potentially exposing ...
Sep 4, 2025A buffer overflow vulnerability in Samsung Exynos processors allows attackers to execute arbitrary code or cause denial of service via specially craft...
Sep 2, 2025This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker can exploit this by setting up a...
Sep 1, 2025This vulnerability allows attackers to read sensitive information from image processing operations by manipulating offset and size parameters. It affe...
Aug 6, 2025This vulnerability allows attackers to read sensitive information from memory when processing specially crafted MBN files. It affects systems using Qu...
Aug 6, 2025An out-of-bounds read vulnerability in PDF-XChange Editor's EMF functionality allows attackers to read memory beyond intended boundaries via specially...
Aug 5, 2025This vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized network attackers to access sensitive information. It affec...
Jul 8, 2025This vulnerability in Samsung Exynos Wi-Fi chips allows out-of-bounds memory access due to missing boundary checks in the STOP_KEEP_ALIVE_OFFLOAD func...
May 27, 2025This vulnerability in Samsung Exynos processors allows attackers to trigger out-of-bounds memory access by sending malformed RRC (Radio Resource Contr...
May 14, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthenticated attackers to read sensitive memory cont...
May 13, 2025An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...
May 13, 2025This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...
Apr 7, 2025This vulnerability in Internet Connection Sharing (ICS) allows attackers to cause a denial of service by exploiting an out-of-bounds read condition. I...
Feb 11, 2025This vulnerability in Internet Connection Sharing (ICS) allows attackers to cause a denial of service condition by exploiting an out-of-bounds read (C...
Feb 11, 2025This vulnerability is an out-of-bounds read (CWE-125) in Apple's WebKit browser engine that could cause unexpected process crashes when processing mal...
Jan 27, 2025This CVE describes an out-of-bounds memory access vulnerability in Apple's web content processing components. Attackers can cause unexpected process c...
Jan 27, 2025An out-of-bounds read vulnerability in Juniper's routing protocol daemon (rpd) allows unauthenticated, adjacent BGP peers to crash the service by send...
Jan 9, 2025This CVE describes a read/write vulnerability in an image decoding module that could allow attackers to manipulate image processing functions. Success...
Dec 12, 2024An unauthenticated attacker can exploit an out-of-bounds heap read vulnerability in the IQ Service (TCP port 9876) on Lorex 2K Indoor Wi-Fi Security C...
Dec 3, 2024CVE-2018-9429 is an out-of-bounds read vulnerability in Android's ItemTable.cpp that could allow information disclosure without requiring elevated pri...
Dec 2, 2024This vulnerability in Android's HEVC video decoder allows an out-of-bounds read when parsing malformed video files. Attackers can cause denial of serv...
Dec 2, 2024CVE-2018-9350 is an out-of-bounds read vulnerability in Android's H.264 decoder that could cause denial of service when processing malicious video fil...
Nov 27, 2024CVE-2017-13320 is an out-of-bounds read vulnerability in the libmpeg2dec library's impeg2d_bit_stream_flush() function. This allows remote attackers t...
Nov 27, 2024CVE-2018-9486 is an out-of-bounds read vulnerability in Android's Bluetooth HID (Human Interface Device) profile implementation. It allows local attac...
Nov 20, 2024CVE-2018-9480 is an out-of-bounds read vulnerability in Android's Bluetooth service that could allow remote attackers to read sensitive information fr...
Nov 20, 2024This vulnerability allows attackers to cause browser denial-of-service by repeatedly writing to history interface attributes. It affects Firefox, Fire...
Oct 29, 2024This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially craft...
Oct 8, 2024This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash) by sending specially crafted re...
Oct 8, 2024About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,927 CVEs classified as CWE-125, with 211 rated critical and 1,162 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free