CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,933
Total CVEs
212
Critical
1,167
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 179
3 Google 169
4 Apple 117
5 Microsoft 113
6 Debian 103
7 Siemens 64
8 Pdf Xchange 58
9 Fedoraproject 57
10 Samsung 51

All Out-of-bounds Read CVEs (1,933)

CVE-2025-55099
6.1

This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio host class implementation when parsing malicious USB descriptor...

Oct 17, 2025
CVE-2025-55097
6.1

This vulnerability allows an attacker to read memory beyond the intended buffer boundaries when parsing USB audio streaming device descriptors. It aff...

Oct 17, 2025
CVE-2025-55098
6.1

This vulnerability allows an attacker to trigger an out-of-bounds read in USBX's audio device parsing function when a malicious USB audio device is co...

Oct 17, 2025
CVE-2025-20026
6.1

An out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software for Windows could allow an unauthenticated attacker on the same network to ...

May 13, 2025
CVE-2025-37149
6.0

An out-of-bounds read vulnerability in HPE ProLiant RL300 Gen11 Server UEFI firmware could allow attackers to read sensitive memory contents. This aff...

Oct 14, 2025
CVE-2024-56662
6.0

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's ACPI NFIT driver. Attackers could exploit this to read kernel memory, pot...

Dec 27, 2024
CVE-2024-27378
6.0

A heap over-read vulnerability exists in Samsung Exynos mobile processors due to missing input validation in the slsi_send_action_frame_cert() functio...

Jun 5, 2024
CVE-2024-27380
6.0

This vulnerability in Samsung Exynos mobile processors allows attackers to read heap memory beyond allocated boundaries through a missing input valida...

Jun 5, 2024
CVE-2024-27382
6.0

This vulnerability in Samsung Exynos mobile processors allows attackers to read heap memory beyond allocated boundaries due to missing input validatio...

Jun 5, 2024
CVE-2023-1544
6.0

This vulnerability in QEMU's VMWare paravirtual RDMA device allows a malicious guest VM driver to allocate excessive page tables, potentially causing ...

Mar 23, 2023
CVE-2025-64098
5.9

This vulnerability in Fast DDS allows remote attackers to cause a denial of service by triggering an out-of-memory condition through specially crafted...

Feb 3, 2026
CVE-2025-9232
5.9

OpenSSL HTTP client API functions have an out-of-bounds read vulnerability when processing IPv6 addresses in URLs with the 'no_proxy' environment vari...

Sep 30, 2025
CVE-2025-7698
5.9

This CVE describes an out-of-bounds read vulnerability in multiple Canon printer drivers. Attackers could exploit this to read sensitive memory conten...

Sep 29, 2025
CVE-2025-23333
5.9

CVE-2025-23333 is an out-of-bounds read vulnerability in NVIDIA Triton Inference Server's Python backend that allows attackers to read memory beyond a...

Aug 6, 2025
CVE-2025-23334
5.9

CVE-2025-23334 is an out-of-bounds read vulnerability in NVIDIA Triton Inference Server's Python backend that could allow information disclosure. Atta...

Aug 6, 2025
CVE-2024-24452
5.9

This vulnerability in Athonet vEPC MME allows attackers to cause a denial of service to cellular networks by exploiting improper memory handling in E-...

Nov 15, 2024
CVE-2024-24454
5.9

This vulnerability allows attackers to cause a denial of service in Athonet vEPC MME cellular network equipment by sending specially crafted E-RAB Mod...

Nov 15, 2024
CVE-2024-24457
5.9

CVE-2024-24457 is an out-of-bounds read vulnerability in Athonet vEPC MME software that allows attackers to cause denial of service to cellular networ...

Nov 15, 2024
CVE-2024-24459
5.9

This vulnerability allows attackers to cause a denial of service to cellular networks by exploiting an invalid memory access in Athonet vEPC MME when ...

Nov 15, 2024
CVE-2024-8929
5.8

A memory disclosure vulnerability in PHP's MySQL client allows a malicious MySQL server to read heap memory from the client. This could expose sensiti...

Nov 22, 2024
CVE-2023-39176
5.8

This vulnerability in the Linux kernel's ksmbd module allows attackers to read past allocated buffer boundaries when processing SMB2 requests with tra...

Nov 18, 2024
CVE-2025-23272
5.7

The NVIDIA nvJPEG library contains an out-of-bounds read vulnerability when processing specially crafted JPEG files. This could allow attackers to rea...

Sep 24, 2025
CVE-2025-48002
5.7

An integer overflow vulnerability in Windows Hyper-V allows authenticated attackers on adjacent networks to potentially read sensitive memory contents...

Jul 8, 2025
CVE-2025-29974
5.7

An integer underflow vulnerability in the Windows Kernel allows attackers on adjacent networks to read kernel memory and potentially disclose sensitiv...

May 13, 2025
CVE-2017-13317
5.7

CVE-2017-13317 is an out-of-bounds read vulnerability in Android's HEIF image decoder that could allow remote attackers to read sensitive memory infor...

Jan 28, 2025
CVE-2024-32607
5.7

CVE-2024-32607 is a memory corruption vulnerability in the HDF5 library that can cause a segmentation fault (SEGV) when closing attributes, potentiall...

May 14, 2024
CVE-2023-51592
5.7

This vulnerability in BlueZ's AVRCP protocol allows network-adjacent attackers to read sensitive information from memory via Bluetooth when a user con...

May 3, 2024
CVE-2023-51580
5.7

This vulnerability in BlueZ's AVRCP protocol allows attackers to read memory beyond allocated buffers via Bluetooth, potentially disclosing sensitive ...

May 3, 2024
CVE-2023-28448
5.7

This vulnerability in the Versionize crate allows out-of-bounds memory accesses during deserialization of FamStructWrapper data structures. It affects...

Mar 24, 2023
CVE-2025-31937
5.6

An out-of-bounds read vulnerability in Intel QAT Windows software before version 2.6.0 allows authenticated local attackers to cause denial of service...

Nov 11, 2025
CVE-2024-33607
5.6

This vulnerability is an out-of-bounds read in Intel TDX module software that could allow an authenticated attacker with local access to read sensitiv...

Aug 12, 2025
CVE-2026-27270
5.5

Adobe Illustrator versions 29.8.4, 30.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive informa...

Mar 10, 2026
CVE-2026-27219
5.5

Substance3D Painter versions 11.1.2 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. Attackers could potentia...

Mar 10, 2026
CVE-2026-31793
5.5

A segmentation fault vulnerability in iccDEV's CIccCalculatorFunc::ApplySequence() function allows denial of service through invalid pointer reads. Th...

Mar 10, 2026
CVE-2026-25180
5.5

CVE-2026-25180 is an out-of-bounds read vulnerability in Microsoft Graphics Component that allows local attackers to read memory beyond allocated buff...

Mar 10, 2026
CVE-2026-24282
5.5

CVE-2026-24282 is an out-of-bounds read vulnerability in the Push Message Routing Service that allows an authorized attacker to read memory beyond all...

Mar 10, 2026
CVE-2024-56807
5.5

An out-of-bounds read vulnerability in QNAP Media Streaming add-on allows attackers with local network access to read sensitive memory contents. This ...

Feb 11, 2026
CVE-2026-21348
5.5

Substance3D Modeler versions 1.22.5 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. An attacker could exploi...

Feb 10, 2026
CVE-2026-21339
5.5

Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. Attackers could exploit...

Feb 10, 2026
CVE-2026-21340
5.5

Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. An attacker could explo...

Feb 10, 2026
CVE-2026-21337
5.5

CVE-2026-21337 is an out-of-bounds read vulnerability in Substance3D Designer that could allow memory exposure when processing malicious files. Attack...

Feb 10, 2026
CVE-2026-21314
5.5

Adobe Audition versions 25.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive information from mem...

Feb 10, 2026
CVE-2026-21261
5.5

This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive infor...

Feb 10, 2026
CVE-2026-25920
5.5

A heap out-of-bounds read vulnerability in SumatraPDF's MOBI HuffDic decompressor allows reading beyond allocated memory bounds when processing malici...

Feb 9, 2026
CVE-2025-46306
5.5

This vulnerability allows attackers to read sensitive memory contents by tricking users into opening malicious Keynote files. It affects macOS, iOS, i...

Jan 28, 2026
CVE-2026-23951
5.5

SumatraPDF contains an off-by-one error when processing specially crafted Mobi files, causing an integer underflow that leads to an out-of-bounds heap...

Jan 22, 2026
CVE-2026-21308
5.5

Substance3D Designer versions 15.0.3 and earlier contain an out-of-bounds read vulnerability that could allow memory disclosure. Attackers could explo...

Jan 13, 2026
CVE-2026-21278
5.5

Adobe InDesign versions 21.0, 19.5.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive informatio...

Jan 13, 2026
CVE-2026-20835
5.5

This vulnerability allows an authorized attacker to perform an out-of-bounds read in the Capability Access Management Service (camsvc), potentially di...

Jan 13, 2026
CVE-2026-20829
5.5

This vulnerability is an out-of-bounds read in Windows TPM (Trusted Platform Module) that allows an authorized attacker to read memory beyond allocate...

Jan 13, 2026

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,933 CVEs classified as CWE-125, with 212 rated critical and 1,167 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free