CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,950
Total CVEs
214
Critical
1,182
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
109
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 181
3 Google 169
4 Apple 126
5 Debian 113
6 Microsoft 113
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,950)

CVE-2023-51567
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated bounds when parsing malicious OXPS files, potentially disclosin...

May 3, 2024
CVE-2023-44433
5.5

This vulnerability in Kofax Power PDF allows attackers to read sensitive information from memory by tricking users into opening malicious PDF files. I...

May 3, 2024
CVE-2023-42110
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when processing malicious EMF files, potentially disc...

May 3, 2024
CVE-2023-42113
5.5

This vulnerability in PDF-XChange Editor allows remote attackers to disclose sensitive information by tricking users into opening malicious EMF files....

May 3, 2024
CVE-2023-42107
5.5

This vulnerability in PDF-XChange Editor allows attackers to read sensitive information from memory when users open malicious EMF files. The flaw exis...

May 3, 2024
CVE-2023-42087
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when processing malicious EMF files, potentially disc...

May 3, 2024
CVE-2023-42084
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing EMF files, allowing attackers to disclose sensitive information from memo...

May 3, 2024
CVE-2023-42073
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated boundaries when processing malicious PDF files with embedded...

May 3, 2024
CVE-2023-42065
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when parsing malicious JP2 files, potentially disclos...

May 3, 2024
CVE-2023-42067
5.5

This vulnerability in PDF-XChange Editor allows remote attackers to read sensitive information from memory when processing malicious JB2 files. Attack...

May 3, 2024
CVE-2023-42053
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when processing malicious U3D files, potentially disc...

May 3, 2024
CVE-2023-42049
5.5

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing EMF files, allowing attackers to disclose sensitive information from memo...

May 3, 2024
CVE-2023-40469
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when parsing malicious XPS files, potentially disclos...

May 3, 2024
CVE-2023-40473
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated boundaries when processing malicious PDF files containing Ja...

May 3, 2024
CVE-2023-39504
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds when parsing malicious OXPS files, potentially disclo...

May 3, 2024
CVE-2023-39487
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated bounds, potentially disclosing sensitive information. Attack...

May 3, 2024
CVE-2023-39483
5.5

This vulnerability in PDF-XChange Editor allows attackers to read memory beyond allocated buffers when parsing malicious J2K files, potentially disclo...

May 3, 2024
CVE-2023-38085
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated bounds when parsing malicious JP2 files, potentially disclosing...

May 3, 2024
CVE-2023-37356
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated buffers when processing malicious GIF files, potentially disclo...

May 3, 2024
CVE-2023-37358
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated bounds when processing malicious U3D files, potentially disclos...

May 3, 2024
CVE-2023-38077
5.5

This vulnerability in Kofax Power PDF allows attackers to disclose sensitive information by tricking users into opening malicious U3D files. The flaw ...

May 3, 2024
CVE-2023-37351
5.5

This vulnerability in Kofax Power PDF allows attackers to read memory beyond allocated boundaries when parsing malicious PDF files, potentially disclo...

May 3, 2024
CVE-2023-37353
5.5

This vulnerability in Kofax Power PDF allows remote attackers to disclose sensitive information by tricking users into opening malicious JPG files. Th...

May 3, 2024
CVE-2024-26980
5.5

A slab-out-of-bounds read vulnerability in the Linux kernel's ksmbd SMB server module allows attackers to read kernel memory beyond allocated buffers....

May 1, 2024
CVE-2022-43640
5.5

CVE-2022-43640 is an out-of-bounds read vulnerability in Foxit PDF Reader that allows attackers to disclose sensitive information from affected system...

Mar 29, 2023
CVE-2022-43611
5.5

CVE-2022-43611 is an out-of-bounds read vulnerability in CorelDRAW's BMP image parser that allows attackers to disclose sensitive information. Success...

Mar 29, 2023
CVE-2022-43615
5.5

This vulnerability in CorelDRAW Graphics Suite allows attackers to read beyond allocated memory bounds when parsing malicious PDF files. Attackers can...

Mar 29, 2023
CVE-2022-37383
5.5

This vulnerability in Foxit PDF Reader allows remote attackers to read sensitive information from memory by exploiting a JavaScript flaw in Doc object...

Mar 29, 2023
CVE-2022-37386
5.5

This vulnerability in Foxit PDF Reader allows remote attackers to read sensitive information from memory by exploiting an out-of-bounds read in the re...

Mar 29, 2023
CVE-2022-37373
5.5

CVE-2022-37373 is an out-of-bounds read vulnerability in PDF-XChange Editor that allows remote attackers to disclose sensitive information. Attackers ...

Mar 29, 2023
CVE-2022-37360
5.5

CVE-2022-37360 is an out-of-bounds read vulnerability in PDF-XChange Editor's EMF file parser that allows remote attackers to disclose sensitive infor...

Mar 29, 2023
CVE-2022-37368
5.5

CVE-2022-37368 is an out-of-bounds read vulnerability in PDF-XChange Editor's Doc object handling that allows information disclosure. Attackers can ex...

Mar 29, 2023
CVE-2022-37352
5.5

CVE-2022-37352 is an out-of-bounds read vulnerability in PDF-XChange Editor's WMF file parser. Attackers can exploit this by tricking users into openi...

Mar 29, 2023
CVE-2022-28309
5.5

CVE-2022-28309 is an out-of-bounds read vulnerability in Bentley View's 3DS file parser that allows remote attackers to disclose sensitive information...

Mar 29, 2023
CVE-2022-28312
5.5

This vulnerability in Bentley MicroStation CONNECT allows remote attackers to disclose sensitive information by exploiting a buffer read overflow when...

Mar 29, 2023
CVE-2023-26350
5.5

CVE-2023-26350 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory information. This affec...

Mar 28, 2023
CVE-2023-26352
5.5

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. T...

Mar 28, 2023
CVE-2023-26354
5.5

CVE-2023-26354 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory information. This affec...

Mar 28, 2023
CVE-2023-26356
5.5

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. T...

Mar 28, 2023
CVE-2023-26339
5.5

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory information...

Mar 28, 2023
CVE-2023-26341
5.5

This vulnerability in Adobe Dimension allows an attacker to read memory outside intended bounds by tricking a user into opening a malicious file, pote...

Mar 28, 2023
CVE-2023-26343
5.5

CVE-2023-26343 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory information. This could...

Mar 28, 2023
CVE-2023-26345
5.5

Adobe Dimension versions 3.4.7 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. T...

Mar 28, 2023
CVE-2023-26348
5.5

CVE-2023-26348 is an out-of-bounds read vulnerability in Adobe Dimension that could allow an attacker to read sensitive memory contents when a user op...

Mar 28, 2023
CVE-2023-25877
5.5

Adobe Substance 3D Stager versions 2.0.0 and earlier contain an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory...

Mar 27, 2023
CVE-2023-25875
5.5

Adobe Substance 3D Stager versions 2.0.0 and earlier contain an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory...

Mar 27, 2023
CVE-2023-21019
5.5

This CVE describes a heap buffer overflow vulnerability in Android's H.264 video encoder that allows local information disclosure without user interac...

Mar 24, 2023
CVE-2023-20973
5.5

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth stack that could allow local information disclosure. Attackers with syst...

Mar 24, 2023
CVE-2023-20980
5.5

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth stack that could allow local information disclosure. Attackers with syst...

Mar 24, 2023
CVE-2021-0584
5.5

This vulnerability in Android's Parcel component allows local attackers to read memory beyond intended boundaries without requiring user interaction o...

Aug 17, 2021

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free