CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,948
Total CVEs
214
Critical
1,180
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 179
3 Google 169
4 Apple 126
5 Microsoft 113
6 Debian 112
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,948)

CVE-2026-24282
5.5

CVE-2026-24282 is an out-of-bounds read vulnerability in the Push Message Routing Service that allows an authorized attacker to read memory beyond all...

Mar 10, 2026
CVE-2024-56807
5.5

An out-of-bounds read vulnerability in QNAP Media Streaming add-on allows attackers with local network access to read sensitive memory contents. This ...

Feb 11, 2026
CVE-2026-21348
5.5

Substance3D Modeler versions 1.22.5 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. An attacker could exploi...

Feb 10, 2026
CVE-2026-21339
5.5

Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. Attackers could exploit...

Feb 10, 2026
CVE-2026-21340
5.5

Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. An attacker could explo...

Feb 10, 2026
CVE-2026-21337
5.5

CVE-2026-21337 is an out-of-bounds read vulnerability in Substance3D Designer that could allow memory exposure when processing malicious files. Attack...

Feb 10, 2026
CVE-2026-21314
5.5

Adobe Audition versions 25.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive information from mem...

Feb 10, 2026
CVE-2026-21261
5.5

This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive infor...

Feb 10, 2026
CVE-2026-25920
5.5

A heap out-of-bounds read vulnerability in SumatraPDF's MOBI HuffDic decompressor allows reading beyond allocated memory bounds when processing malici...

Feb 9, 2026
CVE-2025-46306
5.5

This vulnerability allows attackers to read sensitive memory contents by tricking users into opening malicious Keynote files. It affects macOS, iOS, i...

Jan 28, 2026
CVE-2026-23951
5.5

SumatraPDF contains an off-by-one error when processing specially crafted Mobi files, causing an integer underflow that leads to an out-of-bounds heap...

Jan 22, 2026
CVE-2026-21308
5.5

Substance3D Designer versions 15.0.3 and earlier contain an out-of-bounds read vulnerability that could allow memory disclosure. Attackers could explo...

Jan 13, 2026
CVE-2026-21278
5.5

Adobe InDesign versions 21.0, 19.5.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive informatio...

Jan 13, 2026
CVE-2026-20835
5.5

This vulnerability allows an authorized attacker to perform an out-of-bounds read in the Capability Access Management Service (camsvc), potentially di...

Jan 13, 2026
CVE-2026-20829
5.5

This vulnerability is an out-of-bounds read in Windows TPM (Trusted Platform Module) that allows an authorized attacker to read memory beyond allocate...

Jan 13, 2026
CVE-2025-14421
5.5

This vulnerability in pdfforge PDF Architect allows attackers to read memory beyond allocated bounds when parsing malicious PDF files, potentially dis...

Dec 23, 2025
CVE-2025-14410
5.5

This vulnerability in Soda PDF Desktop allows remote attackers to disclose sensitive information by tricking users into opening malicious PDF files. T...

Dec 23, 2025
CVE-2025-14411
5.5

This vulnerability in Soda PDF Desktop allows attackers to read memory beyond allocated boundaries when parsing malicious PDF files, potentially discl...

Dec 23, 2025
CVE-2025-36921
5.5

This vulnerability allows an attacker to read memory beyond intended boundaries in the baseband firmware's ProtocolPsUnthrottleApn() function. Exploit...

Dec 11, 2025
CVE-2025-48622
5.5

This CVE describes an out-of-bounds read vulnerability in the ProcessArea function of dng_misc_opcodes.cpp within Android's DNG SDK. It allows local i...

Dec 8, 2025
CVE-2025-61843
5.5

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive information from me...

Nov 11, 2025
CVE-2025-61844
5.5

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive information from me...

Nov 11, 2025
CVE-2025-61845
5.5

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure. Attackers could exploit this b...

Nov 11, 2025
CVE-2025-61840
5.5

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive information from me...

Nov 11, 2025
CVE-2025-61841
5.5

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive memory informatio...

Nov 11, 2025
CVE-2025-60706
5.5

This vulnerability allows an authorized attacker with local access to a Windows Hyper-V host to read memory outside intended boundaries, potentially e...

Nov 11, 2025
CVE-2025-59513
5.5

This vulnerability allows an authorized attacker to read memory outside the intended buffer in Windows Bluetooth RFCOM Protocol Driver, potentially ex...

Nov 11, 2025
CVE-2025-43377
5.5

This CVE describes an out-of-bounds read vulnerability in Apple operating systems that could allow a malicious app to cause a denial-of-service condit...

Nov 4, 2025
CVE-2025-54269
5.5

Adobe Animate versions 23.0.13, 24.0.10 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive informati...

Oct 15, 2025
CVE-2025-55695
5.5

CVE-2025-55695 is an out-of-bounds read vulnerability in Windows WLAN Auto Config Service that allows authenticated local attackers to read memory con...

Oct 14, 2025
CVE-2025-54237
5.5

Substance3D Stager versions 3.1.3 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure when processing malicious f...

Sep 16, 2025
CVE-2025-43366
5.5

This CVE describes an out-of-bounds read vulnerability in macOS that could allow an application to access coprocessor memory. The vulnerability affect...

Sep 15, 2025
CVE-2025-43346
5.5

An out-of-bounds memory access vulnerability in Apple media file processing allows attackers to cause application crashes or corrupt process memory by...

Sep 15, 2025
CVE-2025-43326
5.5

An out-of-bounds read vulnerability in macOS allows applications to access sensitive user data without proper authorization. This affects macOS Sonoma...

Sep 15, 2025
CVE-2025-54240
5.5

CVE-2025-54240 is an out-of-bounds read vulnerability in Adobe After Effects that could expose memory contents and potentially disclose sensitive info...

Sep 9, 2025
CVE-2025-54241
5.5

Adobe After Effects versions 25.3, 24.6.7 and earlier contain an out-of-bounds read vulnerability that could expose memory contents, potentially leaki...

Sep 9, 2025
CVE-2025-54239
5.5

Adobe After Effects versions 25.3, 24.6.7 and earlier contain an out-of-bounds read vulnerability that could allow memory exposure and disclosure of s...

Sep 9, 2025
CVE-2025-9323
5.5

This vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by tricking users into opening malicious JP2 files. T...

Sep 2, 2025
CVE-2025-9324
5.5

Foxit PDF Reader contains an out-of-bounds read vulnerability when parsing PRC files, allowing attackers to disclose sensitive information from affect...

Sep 2, 2025
CVE-2025-9325
5.5

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated bounds when parsing malicious PRC files, potentially disclosin...

Sep 2, 2025
CVE-2025-54080
5.5

CVE-2025-54080 is an out-of-bounds read vulnerability in Exiv2 library versions 0.28.5 and earlier. An attacker can cause denial of service by crashin...

Aug 29, 2025
CVE-2025-54238
5.5

Adobe Dimension versions 4.1.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. U...

Aug 12, 2025
CVE-2025-54228
5.5

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents by tricking users into opening mal...

Aug 12, 2025
CVE-2025-54235
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54214
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow attackers to read sensitive memory contents. Affected users ...

Aug 12, 2025
CVE-2025-54203
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54204
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54205
5.5

Substance3D Sampler versions 5.0.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory content...

Aug 12, 2025
CVE-2025-54195
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54197
5.5

CVE-2025-54197 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow an attacker to read sensitive memory contents. This affe...

Aug 12, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,948 CVEs classified as CWE-125, with 214 rated critical and 1,180 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free