CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,927
Total CVEs
211
Critical
1,162
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 302
2 Adobe 179
3 Google 167
4 Apple 117
5 Microsoft 113
6 Debian 102
7 Siemens 64
8 Pdf Xchange 58
9 Fedoraproject 56
10 Samsung 51

All Out-of-bounds Read CVEs (1,927)

CVE-2026-20421
6.5

This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...

Feb 2, 2026
CVE-2026-23569
6.5

An out-of-bounds read vulnerability in TeamViewer DEX Client's Content Distribution Service allows remote attackers to leak stack memory and cause den...

Jan 29, 2026
CVE-2025-71004
6.5

A segmentation violation vulnerability in OneFlow's logical_or component allows attackers to crash the application via specially crafted input, causin...

Jan 28, 2026
CVE-2025-71001
6.5

A segmentation violation vulnerability in OneFlow's flow.column_stack component allows attackers to cause Denial of Service (DoS) through crafted inpu...

Jan 28, 2026
CVE-2025-67810
6.5

This vulnerability allows authenticated attackers to read arbitrary files from the server filesystem in Area9 Rhapsode 1.47.3 by exploiting operation,...

Jan 9, 2026
CVE-2025-52871
6.5

An out-of-bounds read vulnerability in QNAP License Center allows authenticated remote attackers to read sensitive memory contents. This affects users...

Jan 2, 2026
CVE-2025-68431
6.5

CVE-2025-68431 is a heap buffer over-read vulnerability in libheif's overlay image processing. Attackers can craft malicious HEIF files to trigger mem...

Dec 29, 2025
CVE-2025-68382
6.5

An out-of-bounds read vulnerability in the NFS protocol dissector allows unauthenticated remote attackers to cause a denial-of-service via process cra...

Dec 18, 2025
CVE-2025-59391
6.5

A memory disclosure vulnerability in libcoap's OSCORE configuration parser allows attackers to read memory beyond string boundaries in the .rodata sec...

Dec 8, 2025
CVE-2025-58113
6.5

An out-of-bounds read vulnerability in PDF-XChange Editor's EMF functionality allows attackers to read memory beyond intended boundaries via specially...

Dec 2, 2025
CVE-2025-63523
6.5

FeehiCMS version 2.1.1 has a server-side validation flaw where parameters marked as read-only on the client side can be modified by authenticated atta...

Dec 1, 2025
CVE-2025-57697
6.5

AstrBot Project v3.5.22 contains an arbitrary file read vulnerability in the _encode_image_bs64 function that allows attackers to read any file on the...

Nov 7, 2025
CVE-2025-62492
6.5

A floating-point precision error in QuickJS's TypedArray.prototype.indexOf() allows out-of-bounds memory read when using extremely small negative from...

Oct 16, 2025
CVE-2025-62493
6.5

This vulnerability in QuickJS engine allows attackers to read memory beyond allocated BigInt buffers during string conversion, potentially exposing se...

Oct 16, 2025
CVE-2025-55091
6.5

This vulnerability in NetX Duo's _nx_ip_packet_receive() function allows an attacker to cause an out-of-bounds read by sending specially crafted Ether...

Oct 16, 2025
CVE-2025-55700
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read memory contents over the...

Oct 14, 2025
CVE-2025-58717
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read memory contents they sho...

Oct 14, 2025
CVE-2025-55225
6.5

This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Windows Routing and Remote Access Service (RRAS), pot...

Sep 9, 2025
CVE-2025-54095
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...

Sep 9, 2025
CVE-2025-54096
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...

Sep 9, 2025
CVE-2025-54097
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...

Sep 9, 2025
CVE-2025-26441
6.5

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth SDP discovery component that could allow remote attackers to read sensit...

Sep 4, 2025
CVE-2024-56189
6.5

This vulnerability allows authenticated remote attackers to read memory beyond intended boundaries in SAEMM_RadioMessageCodec.c, potentially exposing ...

Sep 4, 2025
CVE-2025-32100
6.5

A buffer overflow vulnerability in Samsung Exynos processors allows attackers to execute arbitrary code or cause denial of service via specially craft...

Sep 2, 2025
CVE-2025-20703
6.5

This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker can exploit this by setting up a...

Sep 1, 2025
CVE-2025-21464
6.5

This vulnerability allows attackers to read sensitive information from image processing operations by manipulating offset and size parameters. It affe...

Aug 6, 2025
CVE-2025-21465
6.5

This vulnerability allows attackers to read sensitive information from memory when processing specially crafted MBN files. It affects systems using Qu...

Aug 6, 2025
CVE-2025-47152
6.5

An out-of-bounds read vulnerability in PDF-XChange Editor's EMF functionality allows attackers to read memory beyond intended boundaries via specially...

Aug 5, 2025
CVE-2025-49671
6.5

This vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized network attackers to access sensitive information. It affec...

Jul 8, 2025
CVE-2024-49197
6.5

This vulnerability in Samsung Exynos Wi-Fi chips allows out-of-bounds memory access due to missing boundary checks in the STOP_KEEP_ALIVE_OFFLOAD func...

May 27, 2025
CVE-2024-56427
6.5

This vulnerability in Samsung Exynos processors allows attackers to trigger out-of-bounds memory access by sending malformed RRC (Radio Resource Contr...

May 14, 2025
CVE-2025-29961
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthenticated attackers to read sensitive memory cont...

May 13, 2025
CVE-2025-29836
6.5

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory content...

May 13, 2025
CVE-2025-20659
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Apr 7, 2025
CVE-2025-21254
6.5

This vulnerability in Internet Connection Sharing (ICS) allows attackers to cause a denial of service by exploiting an out-of-bounds read condition. I...

Feb 11, 2025
CVE-2025-21212
6.5

This vulnerability in Internet Connection Sharing (ICS) allows attackers to cause a denial of service condition by exploiting an out-of-bounds read (C...

Feb 11, 2025
CVE-2025-24162
6.5

This vulnerability is an out-of-bounds read (CWE-125) in Apple's WebKit browser engine that could cause unexpected process crashes when processing mal...

Jan 27, 2025
CVE-2024-54478
6.5

This CVE describes an out-of-bounds memory access vulnerability in Apple's web content processing components. Attackers can cause unexpected process c...

Jan 27, 2025
CVE-2025-21600
6.5

An out-of-bounds read vulnerability in Juniper's routing protocol daemon (rpd) allows unauthenticated, adjacent BGP peers to crash the service by send...

Jan 9, 2025
CVE-2024-54108
6.5

This CVE describes a read/write vulnerability in an image decoding module that could allow attackers to manipulate image processing functions. Success...

Dec 12, 2024
CVE-2024-52545
6.5

An unauthenticated attacker can exploit an out-of-bounds heap read vulnerability in the IQ Service (TCP port 9876) on Lorex 2K Indoor Wi-Fi Security C...

Dec 3, 2024
CVE-2018-9429
6.5

CVE-2018-9429 is an out-of-bounds read vulnerability in Android's ItemTable.cpp that could allow information disclosure without requiring elevated pri...

Dec 2, 2024
CVE-2018-9423
6.5

This vulnerability in Android's HEVC video decoder allows an out-of-bounds read when parsing malformed video files. Attackers can cause denial of serv...

Dec 2, 2024
CVE-2018-9350
6.5

CVE-2018-9350 is an out-of-bounds read vulnerability in Android's H.264 decoder that could cause denial of service when processing malicious video fil...

Nov 27, 2024
CVE-2017-13320
6.5

CVE-2017-13320 is an out-of-bounds read vulnerability in the libmpeg2dec library's impeg2d_bit_stream_flush() function. This allows remote attackers t...

Nov 27, 2024
CVE-2018-9486
6.5

CVE-2018-9486 is an out-of-bounds read vulnerability in Android's Bluetooth HID (Human Interface Device) profile implementation. It allows local attac...

Nov 20, 2024
CVE-2018-9480
6.5

CVE-2018-9480 is an out-of-bounds read vulnerability in Android's Bluetooth service that could allow remote attackers to read sensitive information fr...

Nov 20, 2024
CVE-2024-10464
6.5

This vulnerability allows attackers to cause browser denial-of-service by repeatedly writing to history interface attributes. It affects Firefox, Fire...

Oct 29, 2024
CVE-2024-43555
6.5

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially craft...

Oct 8, 2024
CVE-2024-43537
6.5

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash) by sending specially crafted re...

Oct 8, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,927 CVEs classified as CWE-125, with 211 rated critical and 1,162 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free