CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,929)
This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially craft...
Oct 8, 2024This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash) by sending specially crafted re...
Oct 8, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing M...
Sep 18, 2024An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated boundaries when processing Open...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing M...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...
Sep 18, 2024An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing OpenFlo...
Sep 18, 2024CVE-2024-31186 is an out-of-bounds read vulnerability in the libfluid_msg module of ONF's libfluid library, specifically in the fluid_msg::of13::Queue...
Sep 18, 2024An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing OpenFlo...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...
Sep 18, 2024CVE-2024-31180 is an out-of-bounds read vulnerability in the libfluid_msg module of ONF's libfluid library, specifically in the GroupDesc::unpack func...
Sep 18, 2024An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing OpenF...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing O...
Sep 18, 2024This vulnerability allows attackers to read memory outside the intended buffer boundaries in the libfluid_msg module of ONF libfluid. It affects syste...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers when processing Ope...
Sep 18, 2024An out-of-bounds read vulnerability in ONF libfluid's libfluid_msg module allows attackers to read memory beyond allocated buffers via the fluid_msg::...
Sep 18, 2024This CVE describes an out-of-bounds write vulnerability in ESP-NOW's group message handling where the addrs_num field isn't validated. Attackers can s...
Sep 12, 2024CVE-2024-39775 is an out-of-bounds read vulnerability in OpenHarmony that allows remote attackers to cause information leaks. This affects OpenHarmony...
Sep 2, 2024This vulnerability in Windows Routing and Remote Access Service (RRAS) allows attackers to read sensitive information from memory that should be prote...
Aug 13, 2024This vulnerability allows a remote attacker to read memory outside the intended bounds in Chrome's V8 JavaScript engine. Attackers could potentially l...
Jul 16, 2024This vulnerability in the Windows Layer-2 Bridge Network Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending special...
Jul 9, 2024A memory corruption vulnerability in Silicon Labs multi-protocol gateways allows attackers to crash the OpenThread Border Router application by exploi...
Jun 27, 2024This CVE describes an array index out-of-bounds vulnerability in the Linux kernel's Fibre Channel (libfc) subsystem. An attacker could potentially cau...
May 21, 2024This vulnerability is an out-of-bounds read in Chrome's V8 JavaScript engine that allows a remote attacker to leak cross-site data via a crafted HTML ...
May 1, 2024This vulnerability in macOS allows processing malicious files to cause denial-of-service or potentially leak memory contents. It affects macOS systems...
Apr 11, 2025CVE-2018-9371 is a memory corruption vulnerability in MediaTek Preloader that allows arbitrary peripheral memory mapping due to insufficient access co...
Nov 19, 2024Deep Freeze 9.00.020.5760 contains an out-of-bounds read vulnerability in the FarDisk.sys driver when processing the 0x70014 IOCTL code. This allows a...
Oct 3, 2024This vulnerability allows a remote Bluetooth Low Energy (BLE) client to trigger an out-of-bounds read and potential memory corruption in ESP-IDF devic...
Feb 4, 2026An out-of-bounds read vulnerability in Apple operating systems allows attackers to disclose user information by parsing malicious files. This affects ...
May 12, 2025This vulnerability allows local privileged attackers to read and write out-of-bounds memory in Samsung mPOS TUI trustlet software. It affects Samsung ...
Feb 4, 2025A race condition vulnerability in the Linux kernel's s390/cpum_sf component allows concurrent memory allocation of Sample Data Blocks (SDBs) for Perfo...
Dec 28, 2024This vulnerability in Zephyr RTOS's UTF-8 string truncation function allows reading memory outside the intended buffer when processing empty strings. ...
Oct 4, 2024This vulnerability in MediaTek's imgsys component allows local information disclosure due to missing bounds checking. Attackers with system privileges...
Apr 1, 2024This CVE describes an out-of-bounds read vulnerability in the media subsystem that could allow attackers to read sensitive memory contents or cause sy...
Feb 6, 2026This vulnerability allows an unauthorized local attacker to read memory outside the intended buffer in the Capability Access Management Service (camsv...
Jan 13, 2026An uninitialized stack read vulnerability in Amazon Ion-C library versions before v1.1.4 allows attackers to craft malicious Ion text data that, when ...
Nov 7, 2025This vulnerability allows local attackers to read out-of-bounds memory in Samsung devices by exploiting an out-of-bounds read in the libsavsac.so libr...
Apr 8, 2025This vulnerability in MediaTek's da component allows local attackers to read memory beyond intended boundaries without requiring elevated privileges o...
Dec 2, 2024CVE-2024-20107 is an out-of-bounds read vulnerability in MediaTek's da component that allows local attackers to read memory beyond allocated buffers w...
Nov 4, 2024This vulnerability allows an unauthenticated attacker with local access to read memory outside intended bounds in Dell BSAFE cryptographic libraries. ...
Jul 31, 2024A heap out-of-bounds read vulnerability in iccDEV's CTiffImg::ReadLine() function allows attackers to cause memory disclosure or crashes by processing...
Mar 10, 2026An out-of-bounds read vulnerability in libbiosig's ABF file parser allows attackers to leak sensitive information by providing malicious .abf files. T...
Mar 3, 2026A heap buffer overread vulnerability in util-linux's setpwnam() function allows reading beyond allocated memory when processing 256-byte usernames. Th...
Dec 5, 2025A heap buffer over-read vulnerability in libpng's png_do_quantize function allows attackers to craft malicious PNG files that trigger out-of-bounds me...
Nov 25, 2025A heap buffer over-read vulnerability in libpng's png_write_image_8bit function allows reading up to 2 bytes beyond allocated memory boundaries when p...
Nov 25, 2025This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers with network access via HTTP to compromise the system....
Oct 21, 2025This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio host class implementation when parsing malicious USB descriptor...
Oct 17, 2025This vulnerability allows an attacker to read memory beyond the intended buffer boundaries when parsing USB audio streaming device descriptors. It aff...
Oct 17, 2025This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio device parsing function when a malicious USB audio device is co...
Oct 17, 2025An out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software for Windows could allow an unauthenticated attacker on the same network to ...
May 13, 2025About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,929 CVEs classified as CWE-125, with 211 rated critical and 1,164 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free