CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,708
Total CVEs
147
Critical
1,013
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 86
6 Debian 81
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 50
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,708)

CVE-2022-1587
9.1

An out-of-bounds read vulnerability in PCRE2 library's JIT compiler allows reading memory beyond allocated buffers during recursive regular expression...

May 16, 2022
CVE-2022-1297
9.1

CVE-2022-1297 is an out-of-bounds read vulnerability in the r_bin_ne_get_entrypoints function of radare2, a reverse engineering framework. Attackers c...

Apr 11, 2022
CVE-2021-33293
9.1

CVE-2021-33293 is an out-of-bounds read vulnerability in Panorama Tools libpano13 that could allow attackers to read sensitive memory contents or caus...

Mar 10, 2022
CVE-2022-0717
9.1

CVE-2022-0717 is an out-of-bounds read vulnerability in mruby, a lightweight implementation of the Ruby programming language. This vulnerability could...

Feb 23, 2022
CVE-2022-0623
9.1

CVE-2022-0623 is an out-of-bounds read vulnerability in mruby (a lightweight Ruby implementation) that could allow attackers to read sensitive memory ...

Feb 17, 2022
CVE-2021-24043
9.1

This vulnerability in WhatsApp's RTCP parsing code allows an attacker to read memory outside the allocated heap buffer by sending a specially crafted ...

Feb 2, 2022
CVE-2022-23097
9.1

This vulnerability in Connman's DNS proxy allows attackers to read memory beyond intended boundaries due to improper string length handling. It affect...

Jan 28, 2022
CVE-2022-21722
9.1

CVE-2022-21722 is an out-of-bounds read vulnerability in PJSIP multimedia communication library affecting versions 2.11.1 and prior. This allows attac...

Jan 27, 2022
CVE-2021-37051
9.1

This CVE describes an out-of-bounds read vulnerability in Huawei smartphones that could allow attackers to read memory beyond allocated boundaries. Su...

Dec 8, 2021
CVE-2021-37041
9.1

CVE-2021-37041 is an out-of-bounds read vulnerability in Huawei smartphones caused by improper input verification. This allows attackers to read memor...

Dec 7, 2021
CVE-2021-37016
9.1

This CVE-2021-37016 is an out-of-bounds read vulnerability in Huawei smartphones that allows attackers to read memory beyond allocated buffers. Succes...

Nov 23, 2021
CVE-2021-44144
9.1

CVE-2021-44144 is a heap-based buffer over-read vulnerability in Croatia Control Asterix software version 2.8.1. This vulnerability could allow attack...

Nov 22, 2021
CVE-2020-12141
9.1

CVE-2020-12141 is an out-of-bounds read vulnerability in the SNMP stack of Contiki-NG, an operating system for IoT devices. Attackers can send crafted...

Oct 19, 2021
CVE-2020-19751
9.1

CVE-2020-19751 is a heap-based buffer over-read vulnerability in gpac's gf_odf_del_ipmp_tool function that could allow attackers to read sensitive mem...

Sep 7, 2021
CVE-2021-36159
9.1

CVE-2021-36159 is an out-of-bounds read vulnerability in libfetch's FTP passive mode implementation that occurs when parsing numeric strings. This vul...

Aug 3, 2021
CVE-2021-22354
9.1

This CVE describes an out-of-bounds read vulnerability in Huawei smartphones that could allow attackers to read sensitive information from device memo...

Jun 30, 2021
CVE-2021-20093
9.1

CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter that allows unauthenticated remote attackers to read heap memory contents...

Jun 16, 2021
CVE-2020-11159
9.1

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing WPA/RSN information elements in Wi-Fi beacon and r...

Jun 9, 2021
CVE-2020-11126
9.1

This vulnerability allows attackers to read memory beyond intended boundaries while parsing WLAN frames in Qualcomm Snapdragon chipsets. It affects nu...

Jun 9, 2021
CVE-2021-25287
9.1

This vulnerability is an out-of-bounds read in Pillow's JPEG 2000 decoder that could allow attackers to read sensitive data from memory or cause denia...

Jun 2, 2021
CVE-2020-12403
9.1

This vulnerability in NSS (Network Security Services) allows out-of-bounds reads when using multi-part ChaCha20-POLY1305 encryption, potentially expos...

May 27, 2021
CVE-2021-30194
9.1

CVE-2021-30194 is an out-of-bounds read vulnerability in CODESYS V2 Web-Server that could allow attackers to read sensitive memory contents or cause d...

May 25, 2021
CVE-2018-25009
9.1

A heap-based buffer overflow vulnerability in libwebp's GetLE16() function allows attackers to execute arbitrary code or cause denial of service. This...

May 21, 2021
CVE-2018-25012
9.1

A heap-based buffer overflow vulnerability in libwebp's GetLE24() function allows attackers to execute arbitrary code or cause denial of service by pr...

May 21, 2021
CVE-2020-36330
9.1

CVE-2020-36330 is an out-of-bounds read vulnerability in libwebp versions before 1.0.1, allowing attackers to read sensitive memory data or cause deni...

May 21, 2021
CVE-2021-25847
9.1

This vulnerability in Moxa VPort 06EC-2V Series IP cameras allows attackers to disclose sensitive information by sending specially crafted LLDP packet...

May 10, 2021
CVE-2021-25848
9.1

CVE-2021-25848 is an out-of-bounds read vulnerability in Moxa VPort 06EC-2V Series IP cameras. Attackers can send specially crafted LLDP packets to di...

May 10, 2021
CVE-2021-32055
9.1

CVE-2021-32055 is an out-of-bounds read vulnerability in Mutt and NeoMutt email clients when processing malformed IMAP sequence sets with QRESYNC enab...

May 5, 2021
CVE-2020-11188
9.1

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing SDP values without proper NULL termination checks. It allows att...

Mar 17, 2021
CVE-2020-11190
9.1

CVE-2020-11190 is a buffer over-read vulnerability in Qualcomm Snapdragon chipsets that allows attackers to read memory beyond allocated buffers when ...

Mar 17, 2021
CVE-2020-11222
9.1

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when processing MT SMS messages with maximum length due to improper length ch...

Mar 17, 2021
CVE-2020-11166
9.1

This vulnerability allows an attacker to cause an out-of-bounds read exception by sending specially crafted ROHC headers with excessive padding to aff...

Mar 17, 2021
CVE-2021-28308
9.1

This vulnerability in the fltk Rust crate allows attackers to read memory outside the intended buffer boundaries due to insufficient input validation ...

Mar 12, 2021
CVE-2020-11276
9.1

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets that occurs when processing Wi-Fi P2P (Peer-to-Peer) information elements and...

Feb 22, 2021
CVE-2020-11215
9.1

CVE-2020-11215 is an out-of-bounds read vulnerability in Qualcomm Snapdragon chipsets due to improper length validation when processing VSA attributes...

Jan 21, 2021
CVE-2020-35892
9.1

This vulnerability in the simple-slab Rust crate allows attackers to read memory outside the intended bounds of a data structure via the index() funct...

Dec 31, 2020
CVE-2020-24341
9.1

This vulnerability in picoTCP and picoTCP-NG allows attackers to cause denial-of-service or leak sensitive information by sending specially crafted TC...

Dec 11, 2020
CVE-2020-17441
9.1

This vulnerability in picoTCP allows attackers to trigger an out-of-bounds read during ICMPv6 checksum calculation by sending malformed IPv6 packets w...

Dec 11, 2020
CVE-2020-17467
9.1

This vulnerability in FNET's LLMNR implementation allows attackers to trigger information disclosure by sending specially crafted DNS requests. The la...

Dec 11, 2020
CVE-2020-29657
9.1

CVE-2020-29657 is an out-of-bounds read vulnerability in JerryScript 2.3.0's main-utils.c file that could allow attackers to read sensitive memory con...

Dec 9, 2020
CVE-2020-8747
9.1

This vulnerability allows unauthenticated attackers to read memory outside intended boundaries in Intel AMT subsystems, potentially enabling informati...

Nov 12, 2020
CVE-2020-11169
9.1

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when processing L2CAP Bluetooth packets, caused by missing integer overflow c...

Nov 2, 2020
CVE-2020-16159
9.1

CVE-2020-16159 is a heap out-of-bounds read vulnerability in GoPro's gpmf-parser library version 1.5. Parsing malicious GPMF metadata can cause segmen...

Oct 19, 2020
CVE-2020-0376
9.1

CVE-2020-0376 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory co...

Oct 14, 2020
CVE-2020-14937
9.1

This vulnerability in Contiki-NG's SNMP BER encoder/decoder allows attackers to read or write memory outside allocated buffer boundaries. It affects s...

Aug 18, 2020
CVE-2020-0260
9.1

CVE-2020-0260 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory co...

Aug 11, 2020
CVE-2020-13601
9.0

This vulnerability in Zephyr RTOS allows attackers to read memory beyond allocated bounds during DNS processing, potentially exposing sensitive data o...

May 25, 2021
CVE-2026-0899
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to memory cor...

Jan 20, 2026
CVE-2025-14766
8.8

This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds read/write in Chrome's V8 JavaScript engine. Attackers can...

Dec 16, 2025
CVE-2025-12725
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory writes via a crafted HTML page targeting Chrome's WebGPU implementation on ...

Nov 10, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,708 CVEs classified as CWE-125, with 147 rated critical and 1,013 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free