CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,950
Total CVEs
214
Critical
1,182
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 180
3 Google 169
4 Apple 126
5 Microsoft 113
6 Debian 113
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,950)

CVE-2024-44281
5.5

This vulnerability allows attackers to read memory beyond intended boundaries when parsing malicious files, potentially exposing sensitive user inform...

Oct 28, 2024
CVE-2024-47026
5.5

This vulnerability allows an attacker to read memory beyond intended boundaries in the gsc_gsa_rescue function of gsc_gsa.c, potentially exposing sens...

Oct 25, 2024
CVE-2024-47029
5.5

This vulnerability allows local attackers to read memory beyond intended boundaries in Android's Trusty TEE shared memory manager. It could disclose s...

Oct 25, 2024
CVE-2024-47034
5.5

CVE-2024-47034 is an out-of-bounds read vulnerability in Android that allows local attackers to read memory beyond allocated buffers without requiring...

Oct 25, 2024
CVE-2024-47018
5.5

This vulnerability allows local attackers to read memory beyond intended buffer boundaries in Android's power management unit calibration code. It aff...

Oct 25, 2024
CVE-2024-47420
5.5

Adobe Animate versions 23.0.7, 24.0.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory cont...

Oct 9, 2024
CVE-2024-45145
5.5

Lightroom Desktop has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files...

Oct 9, 2024
CVE-2024-20787
5.5

CVE-2024-20787 is an out-of-bounds read vulnerability in Substance3D Painter that could allow an attacker to read sensitive memory contents when a use...

Oct 9, 2024
CVE-2024-43508
5.5

This vulnerability in the Windows Graphics Component allows an attacker to read sensitive information from memory that should be protected. It affects...

Oct 8, 2024
CVE-2024-44134
5.5

This vulnerability in macOS allows malicious applications to access sensitive location information that should be redacted. It affects macOS systems b...

Sep 17, 2024
CVE-2024-27860
5.5

This memory handling vulnerability in macOS allows applications to read restricted memory regions they shouldn't access. It affects macOS systems befo...

Sep 17, 2024
CVE-2024-41867
5.5

CVE-2024-41867 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to read sensitive memory contents. This coul...

Sep 13, 2024
CVE-2024-41871
5.5

Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory ...

Sep 13, 2024
CVE-2024-41873
5.5

Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory ...

Sep 13, 2024
CVE-2024-41868
5.5

Adobe Audition versions 24.4.1, 23.6.6 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory con...

Sep 11, 2024
CVE-2024-40656
5.5

This vulnerability in Android's ConnectionServiceWrapper allows a malicious app to access images from other user profiles on the same device through a...

Sep 11, 2024
CVE-2024-38382
5.5

This vulnerability in OpenHarmony allows a local attacker to read memory beyond intended boundaries, potentially exposing sensitive information. It af...

Sep 2, 2024
CVE-2022-48932
5.5

A buffer overflow vulnerability in the Linux kernel's mlx5 driver allows attackers to cause kernel memory corruption by creating rules with too many d...

Aug 22, 2024
CVE-2024-41835
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. When ex...

Aug 14, 2024
CVE-2024-41833
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents, potenti...

Aug 14, 2024
CVE-2024-39387
5.5

Adobe Bridge versions 13.0.8, 14.1.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory conte...

Aug 14, 2024
CVE-2024-34135
5.5

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory co...

Aug 14, 2024
CVE-2024-34126
5.5

Adobe Dimension versions 3.4.11 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. ...

Aug 14, 2024
CVE-2024-41861
5.5

CVE-2024-41861 is an out-of-bounds read vulnerability in Adobe Substance3D Sampler that could allow an attacker to read sensitive memory contents. Thi...

Aug 14, 2024
CVE-2024-41863
5.5

CVE-2024-41863 is an out-of-bounds read vulnerability in Adobe Substance3D Sampler that could allow an attacker to read sensitive memory contents when...

Aug 14, 2024
CVE-2024-38151
5.5

This Windows kernel vulnerability allows attackers to read sensitive kernel memory information, potentially exposing system details or credentials. It...

Aug 13, 2024
CVE-2024-34628
5.5

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read arbitrary memory contents. This affects Samsung Notes ...

Aug 7, 2024
CVE-2024-34630
5.5

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents when applying their own binary with a ...

Aug 7, 2024
CVE-2024-34621
5.5

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...

Aug 7, 2024
CVE-2024-34624
5.5

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...

Aug 7, 2024
CVE-2024-34626
5.5

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to potentially read memory contents. This affects Samsung Notes versions p...

Aug 7, 2024
CVE-2024-7537
5.5

This vulnerability in oFono's QMI SMS handling allows local attackers to read beyond allocated buffer boundaries, potentially disclosing sensitive inf...

Aug 6, 2024
CVE-2024-40816
5.5

This CVE describes an out-of-bounds read vulnerability in macOS that could allow a local attacker to cause unexpected system shutdown. The vulnerabili...

Jul 29, 2024
CVE-2024-40779
5.5

This CVE describes an out-of-bounds read vulnerability in Apple's web content processing that could cause unexpected process crashes. It affects multi...

Jul 29, 2024
CVE-2023-42943
5.5

This macOS vulnerability allows applications to access sensitive location information that should be redacted in system logs. It affects macOS users r...

Jul 29, 2024
CVE-2024-41019
5.5

A memory safety vulnerability in the Linux kernel's NTFS3 filesystem driver allows out-of-bounds read access when processing malformed NTFS filesystem...

Jul 29, 2024
CVE-2022-48839
5.5

A memory corruption vulnerability in the Linux kernel's AF_PACKET socket implementation allows local attackers to trigger slab-out-of-bounds access. W...

Jul 16, 2024
CVE-2022-48803
5.5

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's TI PHY driver (phy-j721e-wiz.c) where the clk_div_table array lacks a sen...

Jul 16, 2024
CVE-2024-34140
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Bridge that could allow an attacker to read sensitive memory contents, potentially byp...

Jul 9, 2024
CVE-2024-38056
5.5

This vulnerability in Microsoft Windows Codecs Library allows an attacker to read sensitive information from memory that should be inaccessible. It af...

Jul 9, 2024
CVE-2021-47620
5.5

This CVE addresses an out-of-bounds read vulnerability in the Linux kernel's Bluetooth stack. The flaw could allow attackers to read kernel memory bey...

Jun 20, 2024
CVE-2021-47586
5.5

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's STMMAC Ethernet driver for Rockchip platforms. An attacker could potentia...

Jun 19, 2024
CVE-2023-52878
5.5

This vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem allows out-of-bounds access to the echo_skb buffer, which could cause...

May 21, 2024
CVE-2024-30286
5.5

Adobe Framemaker versions 2020.5, 2022.3 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory c...

May 16, 2024
CVE-2024-30309
5.5

CVE-2024-30309 is an out-of-bounds read vulnerability in Substance3D Painter that could allow an attacker to read sensitive memory contents when a use...

May 16, 2024
CVE-2024-30298
5.5

Adobe Animate versions 24.0.2, 23.0.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory cont...

May 16, 2024
CVE-2024-30312
5.5

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents. Exploit...

May 15, 2024
CVE-2024-30037
5.5

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM privileges through a local expl...

May 14, 2024
CVE-2024-30016
5.5

CVE-2024-30016 is an information disclosure vulnerability in Windows Cryptographic Services that could allow an attacker to read sensitive information...

May 14, 2024
CVE-2021-34949
5.5

This vulnerability in Foxit PDF Reader allows attackers to read sensitive information from memory by tricking users into opening malicious PDF files. ...

May 7, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free