CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,950)
This vulnerability allows attackers to read memory beyond intended boundaries when parsing malicious files, potentially exposing sensitive user inform...
Oct 28, 2024This vulnerability allows an attacker to read memory beyond intended boundaries in the gsc_gsa_rescue function of gsc_gsa.c, potentially exposing sens...
Oct 25, 2024This vulnerability allows local attackers to read memory beyond intended boundaries in Android's Trusty TEE shared memory manager. It could disclose s...
Oct 25, 2024CVE-2024-47034 is an out-of-bounds read vulnerability in Android that allows local attackers to read memory beyond allocated buffers without requiring...
Oct 25, 2024This vulnerability allows local attackers to read memory beyond intended buffer boundaries in Android's power management unit calibration code. It aff...
Oct 25, 2024Adobe Animate versions 23.0.7, 24.0.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory cont...
Oct 9, 2024Lightroom Desktop has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files...
Oct 9, 2024CVE-2024-20787 is an out-of-bounds read vulnerability in Substance3D Painter that could allow an attacker to read sensitive memory contents when a use...
Oct 9, 2024This vulnerability in the Windows Graphics Component allows an attacker to read sensitive information from memory that should be protected. It affects...
Oct 8, 2024This vulnerability in macOS allows malicious applications to access sensitive location information that should be redacted. It affects macOS systems b...
Sep 17, 2024This memory handling vulnerability in macOS allows applications to read restricted memory regions they shouldn't access. It affects macOS systems befo...
Sep 17, 2024CVE-2024-41867 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to read sensitive memory contents. This coul...
Sep 13, 2024Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory ...
Sep 13, 2024Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory ...
Sep 13, 2024Adobe Audition versions 24.4.1, 23.6.6 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory con...
Sep 11, 2024This vulnerability in Android's ConnectionServiceWrapper allows a malicious app to access images from other user profiles on the same device through a...
Sep 11, 2024This vulnerability in OpenHarmony allows a local attacker to read memory beyond intended boundaries, potentially exposing sensitive information. It af...
Sep 2, 2024A buffer overflow vulnerability in the Linux kernel's mlx5 driver allows attackers to cause kernel memory corruption by creating rules with too many d...
Aug 22, 2024This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. When ex...
Aug 14, 2024This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents, potenti...
Aug 14, 2024Adobe Bridge versions 13.0.8, 14.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conte...
Aug 14, 2024Adobe Illustrator versions 28.5, 27.9.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory co...
Aug 14, 2024Adobe Dimension versions 3.4.11 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. ...
Aug 14, 2024CVE-2024-41861 is an out-of-bounds read vulnerability in Adobe Substance3D Sampler that could allow an attacker to read sensitive memory contents. Thi...
Aug 14, 2024CVE-2024-41863 is an out-of-bounds read vulnerability in Adobe Substance3D Sampler that could allow an attacker to read sensitive memory contents when...
Aug 14, 2024This Windows kernel vulnerability allows attackers to read sensitive kernel memory information, potentially exposing system details or credentials. It...
Aug 13, 2024An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read arbitrary memory contents. This affects Samsung Notes ...
Aug 7, 2024An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents when applying their own binary with a ...
Aug 7, 2024An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...
Aug 7, 2024An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...
Aug 7, 2024An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...
Aug 7, 2024This vulnerability in oFono's QMI SMS handling allows local attackers to read beyond allocated buffer boundaries, potentially disclosing sensitive inf...
Aug 6, 2024This CVE describes an out-of-bounds read vulnerability in macOS that could allow a local attacker to cause unexpected system shutdown. The vulnerabili...
Jul 29, 2024This CVE describes an out-of-bounds read vulnerability in Apple's web content processing that could cause unexpected process crashes. It affects multi...
Jul 29, 2024This macOS vulnerability allows applications to access sensitive location information that should be redacted in system logs. It affects macOS users r...
Jul 29, 2024A memory safety vulnerability in the Linux kernel's NTFS3 filesystem driver allows out-of-bounds read access when processing malformed NTFS filesystem...
Jul 29, 2024A memory corruption vulnerability in the Linux kernel's AF_PACKET socket implementation allows local attackers to trigger slab-out-of-bounds access. W...
Jul 16, 2024This CVE describes an out-of-bounds read vulnerability in the Linux kernel's TI PHY driver (phy-j721e-wiz.c) where the clk_div_table array lacks a sen...
Jul 16, 2024This CVE describes an out-of-bounds read vulnerability in Adobe Bridge that could allow an attacker to read sensitive memory contents, potentially byp...
Jul 9, 2024This vulnerability in Microsoft Windows Codecs Library allows an attacker to read sensitive information from memory that should be inaccessible. It af...
Jul 9, 2024This CVE addresses an out-of-bounds read vulnerability in the Linux kernel's Bluetooth stack. The flaw could allow attackers to read kernel memory bey...
Jun 20, 2024This CVE describes an out-of-bounds read vulnerability in the Linux kernel's STMMAC Ethernet driver for Rockchip platforms. An attacker could potentia...
Jun 19, 2024This vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem allows out-of-bounds access to the echo_skb buffer, which could cause...
May 21, 2024Adobe Framemaker versions 2020.5, 2022.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory c...
May 16, 2024CVE-2024-30309 is an out-of-bounds read vulnerability in Substance3D Painter that could allow an attacker to read sensitive memory contents when a use...
May 16, 2024Adobe Animate versions 24.0.2, 23.0.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory cont...
May 16, 2024This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. Exploit...
May 15, 2024This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM privileges through a local expl...
May 14, 2024CVE-2024-30016 is an information disclosure vulnerability in Windows Cryptographic Services that could allow an attacker to read sensitive information...
May 14, 2024This vulnerability in Foxit PDF Reader allows attackers to read sensitive information from memory by tricking users into opening malicious PDF files. ...
May 7, 2024About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free