CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,950
Total CVEs
214
Critical
1,182
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 180
3 Google 169
4 Apple 126
5 Microsoft 113
6 Debian 113
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,950)

CVE-2025-20928
5.5

This vulnerability allows local attackers to read memory outside the intended buffer when Samsung Notes parses WBMP image files. Attackers could poten...

Mar 6, 2025
CVE-2025-20920
5.5

An out-of-bounds read vulnerability in Samsung Notes' action link data handling allows attackers to read memory beyond allocated boundaries. This affe...

Mar 6, 2025
CVE-2025-20922
5.5

An out-of-bounds read vulnerability in Samsung Notes allows attackers to read memory beyond intended boundaries when appending text paragraphs. This a...

Mar 6, 2025
CVE-2025-20914
5.5

An out-of-bounds read vulnerability in Samsung Notes' handwriting content processing allows attackers to read memory beyond allocated boundaries. This...

Mar 6, 2025
CVE-2025-20916
5.5

An out-of-bounds read vulnerability in Samsung Notes' SPen string reading functionality allows attackers to access memory beyond intended boundaries. ...

Mar 6, 2025
CVE-2025-20918
5.5

An out-of-bounds read vulnerability in Samsung Notes allows attackers to read memory beyond allocated boundaries when processing extra data in base co...

Mar 6, 2025
CVE-2025-20042
5.5

This vulnerability in OpenHarmony allows a local attacker to read memory beyond intended boundaries, potentially exposing sensitive information. It af...

Mar 4, 2025
CVE-2025-20648
5.5

This vulnerability in MediaTek's APU (AI Processing Unit) allows an attacker to read memory beyond allocated bounds without requiring user interaction...

Mar 3, 2025
CVE-2025-21124
5.5

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files. T...

Feb 11, 2025
CVE-2025-21374
5.5

This vulnerability in the Windows Client Side Caching (CSC) service allows an authenticated attacker to read sensitive information from system memory....

Jan 14, 2025
CVE-2025-21257
5.5

This vulnerability in Windows WLAN AutoConfig Service allows an authenticated attacker to read sensitive information from system memory. It affects Wi...

Jan 14, 2025
CVE-2024-53839
5.5

This vulnerability allows an attacker to read memory beyond intended boundaries in the GetCellInfoList() function of Android's protocolnetadapter.cpp....

Jan 3, 2025
CVE-2022-44516
5.5

CVE-2022-44516 is an out-of-bounds read vulnerability in Adobe Acrobat Reader DC that allows attackers to bypass ASLR protections by tricking users in...

Dec 19, 2024
CVE-2024-47039
5.5

This vulnerability in Android's BootControl component allows local attackers to read memory beyond intended boundaries without requiring privileges or...

Dec 18, 2024
CVE-2024-49065
5.5

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially craft...

Dec 12, 2024
CVE-2024-53005
5.5

CVE-2024-53005 is an out-of-bounds read vulnerability in Substance3D Modeler that could allow an attacker to read sensitive memory contents when a vic...

Dec 10, 2024
CVE-2024-49547
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow an attacker to read sensitive memory contents. Exploitation ...

Dec 10, 2024
CVE-2024-49549
5.5

Adobe InDesign has an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory contents and potentially bypass ASLR prot...

Dec 10, 2024
CVE-2024-49532
5.5

Adobe Acrobat Reader has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents, potentially bypassing ASLR ...

Dec 10, 2024
CVE-2024-49534
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. When ex...

Dec 10, 2024
CVE-2024-11268
5.5

This vulnerability allows a maliciously crafted PDF file to trigger an out-of-bounds read when parsed by Autodesk Revit. Attackers can exploit this to...

Dec 9, 2024
CVE-2024-9978
5.5

CVE-2024-9978 is an out-of-bounds read vulnerability in OpenHarmony that allows a local attacker to read memory beyond allocated buffers, potentially ...

Dec 3, 2024
CVE-2024-12082
5.5

This vulnerability in OpenHarmony allows a local attacker to read memory beyond intended boundaries, potentially exposing sensitive information. It af...

Dec 3, 2024
CVE-2018-9441
5.5

CVE-2018-9441 is an out-of-bounds read vulnerability in Android's Bluetooth SDP discovery component that could allow local information disclosure. Att...

Dec 3, 2024
CVE-2018-9435
5.5

CVE-2018-9435 is an out-of-bounds read vulnerability in Android's Bluetooth GATT implementation that could allow local information disclosure without ...

Dec 2, 2024
CVE-2024-8844
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated boundaries when parsing malicious PDF files. Users who open ...

Nov 22, 2024
CVE-2024-8846
5.5

This vulnerability in PDF-XChange Editor allows remote attackers to disclose sensitive information by tricking users into opening malicious TIF files....

Nov 22, 2024
CVE-2024-8849
5.5

This vulnerability in PDF-XChange Editor allows remote attackers to read memory beyond allocated bounds when processing malicious PDF files containing...

Nov 22, 2024
CVE-2024-8839
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing JB2 files, allowing attackers to disclose sensitive information from memo...

Nov 22, 2024
CVE-2024-8829
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing EMF files, allowing attackers to disclose sensitive information from memo...

Nov 22, 2024
CVE-2024-8832
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing EMF files, allowing attackers to disclose sensitive information from memo...

Nov 22, 2024
CVE-2024-8835
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated boundaries when parsing malicious JB2 files. It can lead to ...

Nov 22, 2024
CVE-2024-8819
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing U3D files, allowing attackers to disclose sensitive information from memo...

Nov 22, 2024
CVE-2024-8823
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing JB2 files, allowing attackers to disclose sensitive information from memo...

Nov 22, 2024
CVE-2024-5512
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated boundaries when parsing malicious JP2 files, potentially disclo...

Nov 22, 2024
CVE-2024-52998
5.5

CVE-2024-52998 is an out-of-bounds read vulnerability in Substance3D Stager that could allow an attacker to read sensitive memory contents when a vict...

Nov 22, 2024
CVE-2018-9410
5.5

CVE-2018-9410 is an out-of-bounds read vulnerability in Android's font parsing code that allows local information disclosure without requiring user in...

Nov 19, 2024
CVE-2024-49536
5.5

Adobe Audition versions 23.6.9, 24.4.6 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory con...

Nov 15, 2024
CVE-2024-43082
5.5

This Android vulnerability allows malicious apps to access media files from other user profiles on the same device without requiring user interaction....

Nov 13, 2024
CVE-2024-49511
5.5

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when a user opens a malicious file...

Nov 12, 2024
CVE-2024-47435
5.5

CVE-2024-47435 is an out-of-bounds read vulnerability in Substance3D Painter that could allow an attacker to read sensitive memory contents when a vic...

Nov 12, 2024
CVE-2024-47437
5.5

Substance3D Painter versions 10.1.0 and earlier contain an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory cont...

Nov 12, 2024
CVE-2024-47456
5.5

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents...

Nov 12, 2024
CVE-2024-47454
5.5

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents...

Nov 12, 2024
CVE-2024-47445
5.5

CVE-2024-47445 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to read sensitive memory contents. This coul...

Nov 12, 2024
CVE-2024-47449
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Audition that could allow an attacker to read sensitive memory contents. When exploite...

Nov 12, 2024
CVE-2024-45147
5.5

CVE-2024-45147 is an out-of-bounds read vulnerability in Adobe Bridge that could allow an attacker to read sensitive memory, potentially bypassing ASL...

Nov 12, 2024
CVE-2024-49527
5.5

Adobe Animate versions 23.0.7, 24.0.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory cont...

Nov 12, 2024
CVE-2024-50259
5.5

This CVE describes a missing null terminator vulnerability in the Linux kernel's netdevsim driver. When exploited, it could lead to kernel memory corr...

Nov 9, 2024
CVE-2024-44279
5.5

CVE-2024-44279 is an out-of-bounds read vulnerability in macOS file parsing that could allow an attacker to read sensitive information from memory. Th...

Oct 28, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free