CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,929
Total CVEs
211
Critical
1,164
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 302
2 Adobe 179
3 Google 168
4 Apple 117
5 Microsoft 113
6 Debian 102
7 Siemens 64
8 Pdf Xchange 58
9 Fedoraproject 56
10 Samsung 51

All Out-of-bounds Read CVEs (1,929)

CVE-2024-43555
6.5

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially craft...

Oct 8, 2024
CVE-2024-43537
6.5

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash) by sending specially crafted re...

Oct 8, 2024
CVE-2024-31190
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing M...

Sep 18, 2024
CVE-2024-31192
6.5

An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated boundaries when processing Open...

Sep 18, 2024
CVE-2024-31194
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing M...

Sep 18, 2024
CVE-2024-31188
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...

Sep 18, 2024
CVE-2024-31184
6.5

An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing OpenFlo...

Sep 18, 2024
CVE-2024-31186
6.5

CVE-2024-31186 is an out-of-bounds read vulnerability in the libfluid_msg module of ONF's libfluid library, specifically in the fluid_msg::of13::Queue...

Sep 18, 2024
CVE-2024-31176
6.5

An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing OpenFlo...

Sep 18, 2024
CVE-2024-31178
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...

Sep 18, 2024
CVE-2024-31180
6.5

CVE-2024-31180 is an out-of-bounds read vulnerability in the libfluid_msg module of ONF's libfluid library, specifically in the GroupDesc::unpack func...

Sep 18, 2024
CVE-2024-31170
6.5

An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing OpenF...

Sep 18, 2024
CVE-2024-31172
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing O...

Sep 18, 2024
CVE-2024-31174
6.5

This vulnerability allows attackers to read memory outside the intended buffer boundaries in the libfluid_msg module of ONF libfluid. It affects syste...

Sep 18, 2024
CVE-2024-31166
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...

Sep 18, 2024
CVE-2024-31168
6.5

An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers via the fluid_msg::...

Sep 18, 2024
CVE-2024-42484
6.5

This CVE describes an out-of-bounds write vulnerability in ESP-NOW's group message handling where the addrs_num field isn't validated. Attackers can s...

Sep 12, 2024
CVE-2024-39775
6.5

CVE-2024-39775 is an out-of-bounds read vulnerability in OpenHarmony that allows remote attackers to cause information leaks. This affects OpenHarmony...

Sep 2, 2024
CVE-2024-38214
6.5

This vulnerability in Windows Routing and Remote Access Service (RRAS) allows attackers to read sensitive information from memory that should be prote...

Aug 13, 2024
CVE-2024-2884
6.5

This vulnerability allows a remote attacker to read memory outside the intended bounds in Chrome's V8 JavaScript engine. Attackers could potentially l...

Jul 16, 2024
CVE-2024-38102
6.5

This vulnerability in the Windows Layer-2 Bridge Network Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending special...

Jul 9, 2024
CVE-2024-3017
6.5

A memory corruption vulnerability in Silicon Labs multi-protocol gateways allows attackers to crash the OpenThread Border Router application by exploi...

Jun 27, 2024
CVE-2021-47308
6.5

This CVE describes an array index out-of-bounds vulnerability in the Linux kernel's Fibre Channel (libfc) subsystem. An attacker could potentially cau...

May 21, 2024
CVE-2024-4059
6.5

This vulnerability is an out-of-bounds read in Chrome's V8 JavaScript engine that allows a remote attacker to leak cross-site data via a crafted HTML ...

May 1, 2024
CVE-2023-42982
6.4

This vulnerability in macOS allows processing malicious files to cause denial-of-service or potentially leak memory contents. It affects macOS systems...

Apr 11, 2025
CVE-2018-9371
6.4

CVE-2018-9371 is a memory corruption vulnerability in MediaTek Preloader that allows arbitrary peripheral memory mapping due to insufficient access co...

Nov 19, 2024
CVE-2024-8159
6.4

Deep Freeze 9.00.020.5760 contains an out-of-bounds read vulnerability in the FarDisk.sys driver when processing the 0x70014 IOCTL code. This allows a...

Oct 3, 2024
CVE-2026-25508
6.3

This vulnerability allows a remote Bluetooth Low Energy (BLE) client to trigger an out-of-bounds read and potential memory corruption in ESP-IDF devic...

Feb 4, 2026
CVE-2025-31209
6.3

An out-of-bounds read vulnerability in Apple operating systems allows attackers to disclose user information by parsing malicious files. This affects ...

May 12, 2025
CVE-2025-20905
6.3

This vulnerability allows local privileged attackers to read and write out-of-bounds memory in Samsung mPOS TUI trustlet software. It affects Samsung ...

Feb 4, 2025
CVE-2024-56706
6.3

A race condition vulnerability in the Linux kernel's s390/cpum_sf component allows concurrent memory allocation of Sample Data Blocks (SDBs) for Perfo...

Dec 28, 2024
CVE-2024-6443
6.3

This vulnerability in Zephyr RTOS's UTF-8 string truncation function allows reading memory outside the intended buffer when processing empty strings. ...

Oct 4, 2024
CVE-2024-20055
6.3

This vulnerability in MediaTek's imgsys component allows local information disclosure due to missing bounds checking. Attackers with system privileges...

Apr 1, 2024
CVE-2026-24915
6.2

This CVE describes an out-of-bounds read vulnerability in the media subsystem that could allow attackers to read sensitive memory contents or cause sy...

Feb 6, 2026
CVE-2026-20851
6.2

This vulnerability allows an unauthorized local attacker to read memory outside the intended buffer in the Capability Access Management Service (camsv...

Jan 13, 2026
CVE-2025-12829
6.2

An uninitialized stack read vulnerability in Amazon Ion-C library versions before v1.1.4 allows attackers to craft malicious Ion text data that, when ...

Nov 7, 2025
CVE-2025-20944
6.2

This vulnerability allows local attackers to read out-of-bounds memory in Samsung devices by exploiting an out-of-bounds read in the libsavsac.so libr...

Apr 8, 2025
CVE-2024-20136
6.2

This vulnerability in MediaTek's da component allows local attackers to read memory beyond intended boundaries without requiring elevated privileges o...

Dec 2, 2024
CVE-2024-20107
6.2

CVE-2024-20107 is an out-of-bounds read vulnerability in MediaTek's da component that allows local attackers to read memory beyond allocated buffers w...

Nov 4, 2024
CVE-2023-28074
6.2

This vulnerability allows an unauthenticated attacker with local access to read memory outside intended bounds in Dell BSAFE cryptographic libraries. ...

Jul 31, 2024
CVE-2026-31797
6.1

A heap out-of-bounds read vulnerability in iccDEV's CTiffImg::ReadLine() function allows attackers to cause memory disclosure or crashes by processing...

Mar 10, 2026
CVE-2025-64736
6.1

An out-of-bounds read vulnerability in libbiosig's ABF file parser allows attackers to leak sensitive information by providing malicious .abf files. T...

Mar 3, 2026
CVE-2025-14104
6.1

A heap buffer overread vulnerability in util-linux's setpwnam() function allows reading beyond allocated memory when processing 256-byte usernames. Th...

Dec 5, 2025
CVE-2025-64505
6.1

A heap buffer over-read vulnerability in libpng's png_do_quantize function allows attackers to craft malicious PNG files that trigger out-of-bounds me...

Nov 25, 2025
CVE-2025-64506
6.1

A heap buffer over-read vulnerability in libpng's png_write_image_8bit function allows reading up to 2 bytes beyond allocated memory boundaries when p...

Nov 25, 2025
CVE-2025-53055
6.1

This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers with network access via HTTP to compromise the system....

Oct 21, 2025
CVE-2025-55099
6.1

This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio host class implementation when parsing malicious USB descriptor...

Oct 17, 2025
CVE-2025-55097
6.1

This vulnerability allows an attacker to read memory beyond the intended buffer boundaries when parsing USB audio streaming device descriptors. It aff...

Oct 17, 2025
CVE-2025-55098
6.1

This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio device parsing function when a malicious USB audio device is co...

Oct 17, 2025
CVE-2025-20026
6.1

An out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software for Windows could allow an unauthenticated attacker on the same network to ...

May 13, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,929 CVEs classified as CWE-125, with 211 rated critical and 1,164 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free