CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,950
Total CVEs
214
Critical
1,182
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 179
3 Google 169
4 Apple 126
5 Microsoft 113
6 Debian 113
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,950)

CVE-2025-54195
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54197
5.5

CVE-2025-54197 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow an attacker to read sensitive memory contents. This affe...

Aug 12, 2025
CVE-2025-54198
5.5

CVE-2025-54198 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow attackers to read sensitive memory contents when a victi...

Aug 12, 2025
CVE-2025-54199
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54200
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54201
5.5

CVE-2025-54201 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow attackers to read sensitive memory contents when a user ...

Aug 12, 2025
CVE-2025-54202
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54189
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54190
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54191
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54192
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54193
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54194
5.5

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-54186
5.5

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conten...

Aug 12, 2025
CVE-2025-43218
5.5

This vulnerability allows attackers to read memory contents outside the intended buffer when processing malicious USD (Universal Scene Description) fi...

Jul 30, 2025
CVE-2025-38391
5.5

A buffer overflow vulnerability in the Linux kernel's USB Type-C DisplayPort Alt Mode driver allows a malicious USB-C device to trigger a kernel crash...

Jul 25, 2025
CVE-2025-7233
5.5

This vulnerability in IrfanView's CADImage plugin allows attackers to read memory beyond allocated buffers when processing malicious DWG files, potent...

Jul 21, 2025
CVE-2025-27165
5.5

Substance3D Stager versions 3.1.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents...

Jul 8, 2025
CVE-2025-47135
5.5

Adobe Dimension versions 4.1.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. T...

Jul 8, 2025
CVE-2025-49658
5.5

This vulnerability allows a local authenticated attacker to read memory outside the intended buffer in Windows TDX.sys, potentially exposing sensitive...

Jul 8, 2025
CVE-2025-48812
5.5

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive information from t...

Jul 8, 2025
CVE-2025-43587
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to read sensitive memory contents. Successf...

Jul 8, 2025
CVE-2025-21168
5.5

Substance3D Designer versions 14.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory content...

Jul 8, 2025
CVE-2025-21008
5.5

This vulnerability allows local attackers to cause memory corruption via an out-of-bounds read in the libsavsvc.so library when decoding frame headers...

Jul 8, 2025
CVE-2025-20688
5.5

This vulnerability in MediaTek wlan AP driver allows local attackers to read memory beyond intended boundaries, potentially exposing sensitive informa...

Jul 8, 2025
CVE-2025-20690
5.5

This vulnerability in MediaTek wlan AP driver allows local attackers to read memory beyond intended boundaries, potentially exposing sensitive informa...

Jul 8, 2025
CVE-2025-20692
5.5

This CVE describes an out-of-bounds read vulnerability in MediaTek's wlan AP driver that could allow local attackers to read sensitive information fro...

Jul 8, 2025
CVE-2025-47112
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. If expl...

Jun 10, 2025
CVE-2025-47105
5.5

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files. T...

Jun 10, 2025
CVE-2025-33062
5.5

This vulnerability allows an authorized attacker to read memory outside the intended buffer in Windows Storage Management Provider, potentially exposi...

Jun 10, 2025
CVE-2025-33060
5.5

CVE-2025-33060 is an out-of-bounds read vulnerability in Windows Storage Management Provider that allows an authenticated local attacker to read sensi...

Jun 10, 2025
CVE-2025-33058
5.5

CVE-2025-33058 is an out-of-bounds read vulnerability in Windows Storage Management Provider that allows authenticated local attackers to read sensiti...

Jun 10, 2025
CVE-2025-32719
5.5

CVE-2025-32719 is an out-of-bounds read vulnerability in Windows Storage Management Provider that allows authenticated local attackers to read sensiti...

Jun 10, 2025
CVE-2025-24069
5.5

This vulnerability allows an authorized attacker to read memory outside the intended buffer in Windows Storage Management Provider, potentially exposi...

Jun 10, 2025
CVE-2025-24065
5.5

This vulnerability allows an authorized attacker to perform an out-of-bounds read in Windows Storage Management Provider, potentially disclosing sensi...

Jun 10, 2025
CVE-2025-29871
5.5

An out-of-bounds read vulnerability in QNAP File Station 5 allows local attackers with administrator privileges to read sensitive memory data. This af...

Jun 6, 2025
CVE-2025-43551
5.5

Substance3D Stager versions 3.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents...

May 13, 2025
CVE-2025-20976
5.5

An out-of-bounds read vulnerability in Samsung Notes allows attackers to read memory beyond intended boundaries when processing binary text content. T...

May 7, 2025
CVE-2025-32776
5.5

OpenRazer versions before 3.10.2 contain an out-of-bounds read vulnerability in the custom kernel driver. An attacker with local access can write spec...

Apr 15, 2025
CVE-2025-30306
5.5

XMP Toolkit versions 2023.12 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. Thi...

Apr 8, 2025
CVE-2025-30308
5.5

XMP Toolkit versions 2023.12 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. Thi...

Apr 8, 2025
CVE-2025-30303
5.5

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory c...

Apr 8, 2025
CVE-2025-27202
5.5

Adobe Animate versions 24.0.7, 23.0.10 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory con...

Apr 8, 2025
CVE-2025-27184
5.5

CVE-2025-27184 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to read sensitive memory contents. This coul...

Apr 8, 2025
CVE-2025-27186
5.5

Adobe After Effects versions 25.1, 24.6.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory ...

Apr 8, 2025
CVE-2025-20948
5.5

This vulnerability allows local privileged attackers to read out-of-bounds memory in Samsung's cdsp frame secfr trustlet during enrollment. It affects...

Apr 8, 2025
CVE-2025-22003
5.5

This CVE describes a one-byte out-of-bounds read vulnerability in the Linux kernel's CAN (Controller Area Network) ucan driver. The flaw occurs when s...

Apr 3, 2025
CVE-2025-27180
5.5

CVE-2025-27180 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow an attacker to read sensitive memory contents when a vic...

Mar 11, 2025
CVE-2025-20930
5.5

This vulnerability allows local attackers to read out-of-bounds memory in Samsung Notes when parsing JPEG images. Attackers could potentially access s...

Mar 6, 2025
CVE-2025-20932
5.5

This vulnerability allows local attackers to read out-of-bounds memory when parsing RLE-compressed BMP images in Samsung Notes. It affects Samsung Not...

Mar 6, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free