CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,708)
An out-of-bounds read vulnerability in PCRE2 library's JIT compiler allows reading memory beyond allocated buffers during recursive regular expression...
May 16, 2022CVE-2022-1297 is an out-of-bounds read vulnerability in the r_bin_ne_get_entrypoints function of radare2, a reverse engineering framework. Attackers c...
Apr 11, 2022CVE-2021-33293 is an out-of-bounds read vulnerability in Panorama Tools libpano13 that could allow attackers to read sensitive memory contents or caus...
Mar 10, 2022CVE-2022-0717 is an out-of-bounds read vulnerability in mruby, a lightweight implementation of the Ruby programming language. This vulnerability could...
Feb 23, 2022CVE-2022-0623 is an out-of-bounds read vulnerability in mruby (a lightweight Ruby implementation) that could allow attackers to read sensitive memory ...
Feb 17, 2022This vulnerability in WhatsApp's RTCP parsing code allows an attacker to read memory outside the allocated heap buffer by sending a specially crafted ...
Feb 2, 2022This vulnerability in Connman's DNS proxy allows attackers to read memory beyond intended boundaries due to improper string length handling. It affect...
Jan 28, 2022CVE-2022-21722 is an out-of-bounds read vulnerability in PJSIP multimedia communication library affecting versions 2.11.1 and prior. This allows attac...
Jan 27, 2022This CVE describes an out-of-bounds read vulnerability in Huawei smartphones that could allow attackers to read memory beyond allocated boundaries. Su...
Dec 8, 2021CVE-2021-37041 is an out-of-bounds read vulnerability in Huawei smartphones caused by improper input verification. This allows attackers to read memor...
Dec 7, 2021This CVE-2021-37016 is an out-of-bounds read vulnerability in Huawei smartphones that allows attackers to read memory beyond allocated buffers. Succes...
Nov 23, 2021CVE-2021-44144 is a heap-based buffer over-read vulnerability in Croatia Control Asterix software version 2.8.1. This vulnerability could allow attack...
Nov 22, 2021CVE-2020-12141 is an out-of-bounds read vulnerability in the SNMP stack of Contiki-NG, an operating system for IoT devices. Attackers can send crafted...
Oct 19, 2021CVE-2020-19751 is a heap-based buffer over-read vulnerability in gpac's gf_odf_del_ipmp_tool function that could allow attackers to read sensitive mem...
Sep 7, 2021CVE-2021-36159 is an out-of-bounds read vulnerability in libfetch's FTP passive mode implementation that occurs when parsing numeric strings. This vul...
Aug 3, 2021This CVE describes an out-of-bounds read vulnerability in Huawei smartphones that could allow attackers to read sensitive information from device memo...
Jun 30, 2021CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter that allows unauthenticated remote attackers to read heap memory contents...
Jun 16, 2021This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing WPA/RSN information elements in Wi-Fi beacon and r...
Jun 9, 2021This vulnerability allows attackers to read memory beyond intended boundaries while parsing WLAN frames in Qualcomm Snapdragon chipsets. It affects nu...
Jun 9, 2021This vulnerability is an out-of-bounds read in Pillow's JPEG 2000 decoder that could allow attackers to read sensitive data from memory or cause denia...
Jun 2, 2021This vulnerability in NSS (Network Security Services) allows out-of-bounds reads when using multi-part ChaCha20-POLY1305 encryption, potentially expos...
May 27, 2021CVE-2021-30194 is an out-of-bounds read vulnerability in CODESYS V2 Web-Server that could allow attackers to read sensitive memory contents or cause d...
May 25, 2021A heap-based buffer overflow vulnerability in libwebp's GetLE16() function allows attackers to execute arbitrary code or cause denial of service. This...
May 21, 2021A heap-based buffer overflow vulnerability in libwebp's GetLE24() function allows attackers to execute arbitrary code or cause denial of service by pr...
May 21, 2021CVE-2020-36330 is an out-of-bounds read vulnerability in libwebp versions before 1.0.1, allowing attackers to read sensitive memory data or cause deni...
May 21, 2021This vulnerability in Moxa VPort 06EC-2V Series IP cameras allows attackers to disclose sensitive information by sending specially crafted LLDP packet...
May 10, 2021CVE-2021-25848 is an out-of-bounds read vulnerability in Moxa VPort 06EC-2V Series IP cameras. Attackers can send specially crafted LLDP packets to di...
May 10, 2021CVE-2021-32055 is an out-of-bounds read vulnerability in Mutt and NeoMutt email clients when processing malformed IMAP sequence sets with QRESYNC enab...
May 5, 2021This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing SDP values without proper NULL termination checks. It allows att...
Mar 17, 2021CVE-2020-11190 is a buffer over-read vulnerability in Qualcomm Snapdragon chipsets that allows attackers to read memory beyond allocated buffers when ...
Mar 17, 2021This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when processing MT SMS messages with maximum length due to improper length ch...
Mar 17, 2021This vulnerability allows an attacker to cause an out-of-bounds read exception by sending specially crafted ROHC headers with excessive padding to aff...
Mar 17, 2021This vulnerability in the fltk Rust crate allows attackers to read memory outside the intended buffer boundaries due to insufficient input validation ...
Mar 12, 2021This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets that occurs when processing Wi-Fi P2P (Peer-to-Peer) information elements and...
Feb 22, 2021CVE-2020-11215 is an out-of-bounds read vulnerability in Qualcomm Snapdragon chipsets due to improper length validation when processing VSA attributes...
Jan 21, 2021This vulnerability in the simple-slab Rust crate allows attackers to read memory outside the intended bounds of a data structure via the index() funct...
Dec 31, 2020This vulnerability in picoTCP and picoTCP-NG allows attackers to cause denial-of-service or leak sensitive information by sending specially crafted TC...
Dec 11, 2020This vulnerability in picoTCP allows attackers to trigger an out-of-bounds read during ICMPv6 checksum calculation by sending malformed IPv6 packets w...
Dec 11, 2020This vulnerability in FNET's LLMNR implementation allows attackers to trigger information disclosure by sending specially crafted DNS requests. The la...
Dec 11, 2020CVE-2020-29657 is an out-of-bounds read vulnerability in JerryScript 2.3.0's main-utils.c file that could allow attackers to read sensitive memory con...
Dec 9, 2020This vulnerability allows unauthenticated attackers to read memory outside intended boundaries in Intel AMT subsystems, potentially enabling informati...
Nov 12, 2020This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when processing L2CAP Bluetooth packets, caused by missing integer overflow c...
Nov 2, 2020CVE-2020-16159 is a heap out-of-bounds read vulnerability in GoPro's gpmf-parser library version 1.5. Parsing malicious GPMF metadata can cause segmen...
Oct 19, 2020CVE-2020-0376 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory co...
Oct 14, 2020This vulnerability in Contiki-NG's SNMP BER encoder/decoder allows attackers to read or write memory outside allocated buffer boundaries. It affects s...
Aug 18, 2020CVE-2020-0260 is an out-of-bounds read vulnerability in Android System-on-Chip (SoC) components that could allow attackers to read sensitive memory co...
Aug 11, 2020This vulnerability in Zephyr RTOS allows attackers to read memory beyond allocated bounds during DNS processing, potentially exposing sensitive data o...
May 25, 2021This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to memory cor...
Jan 20, 2026This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds read/write in Chrome's V8 JavaScript engine. Attackers can...
Dec 16, 2025This vulnerability allows remote attackers to perform out-of-bounds memory writes via a crafted HTML page targeting Chrome's WebGPU implementation on ...
Nov 10, 2025About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,708 CVEs classified as CWE-125, with 147 rated critical and 1,013 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free