CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,950)
This CVE describes an information disclosure vulnerability in Microsoft Office where uninitialized memory could be read when opening specially crafted...
Sep 11, 2020This CVE-2019-1153 is an information disclosure vulnerability in Microsoft Windows Graphics Component that allows an attacker to read memory contents ...
Aug 14, 2019CVE-2019-1148 is an information disclosure vulnerability in Microsoft Windows Graphics Component that allows authenticated attackers to read memory co...
Aug 14, 2019An out-of-bounds read vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows adjacent network attackers to rea...
Jan 29, 2026This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers with network access via HTTP to compromise the system....
Oct 21, 2025This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows authenticated attackers with low privileges to perform unauthorized data manipul...
Oct 21, 2025This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows authenticated attackers with low privileges to manipulate data via the Rich Text...
Oct 21, 2025An out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack could allow attackers to cause denial of service conditions. Thi...
Aug 6, 2025An out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack could allow attackers to cause denial of service conditions. Thi...
Aug 6, 2025This CVE describes an out-of-bounds access vulnerability in an audio codec module that could allow attackers to cause denial of service conditions. Th...
Aug 6, 2025ImageMagick contains a heap buffer over-read vulnerability in its MAP image decoder that could allow attackers to cause crashes or leak memory by proc...
Feb 24, 2026A memory disclosure vulnerability in libsoup's HTTP Range header processing allows remote attackers to read portions of server memory beyond intended ...
Feb 13, 2026A low-privileged remote attacker can exploit an out-of-bounds read vulnerability in the Device Manager web service to leak memory contents from a priv...
Jan 27, 2026Multiple out-of-bounds read vulnerabilities in a system component that handles data buffers. Insufficient validation of buffer size values allows read...
Jan 13, 2026This CVE describes multiple out-of-bounds read vulnerabilities in a system component that handles data buffers. Insufficient validation of buffer size...
Jan 13, 2026An out-of-bounds read vulnerability in libimagecodec.quram.so allows remote attackers to access memory beyond allocated boundaries. This affects Samsu...
Jan 9, 2026A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to cause out-of-bounds memory access via specially cra...
Dec 19, 2025A memory corruption vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files co...
Dec 19, 2025A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to execute arbitrary code or cause denial of service b...
Dec 19, 2025This vulnerability in SSH Agent servers allows attackers to cause a denial of service by sending specially crafted identity requests that trigger an o...
Nov 19, 2025This vulnerability in NetX Duo's TLS implementation allows attackers to cause an out-of-bounds read by providing malformed PSK length in ClientHello m...
Oct 15, 2025CVE-2025-6632 is an out-of-bounds read vulnerability in Autodesk 3ds Max that allows malicious PSD files to cause crashes, leak sensitive data, or pot...
Aug 6, 2025A memory overread vulnerability in ClamAV's Universal Disk Format (UDF) processing allows unauthenticated remote attackers to cause denial of service ...
Jun 18, 2025An out-of-bounds read vulnerability in Cente middleware TCP/IP Network Series allows attackers to crash affected systems by sending specially crafted ...
Feb 14, 2025This vulnerability causes the cpca process on Check Point Security Management/Domain Management Servers to crash unexpectedly in rare scenarios, creat...
Feb 6, 2025This vulnerability allows local attackers to read arbitrary memory by exploiting an out-of-bounds read in the libsthmbc.so library when processing mal...
Feb 4, 2025This vulnerability allows local attackers to read arbitrary memory through an out-of-bounds read in the svp8t table handling of libsthmbc.so library. ...
Feb 4, 2025This CVE describes an out-of-bounds memory access vulnerability in Apple's coprocessor handling that could allow a malicious app to corrupt coprocesso...
Jan 27, 2025This CVE describes an unchecked return value and out-of-bounds read vulnerability in FFmpeg's pan audio filter that could allow reading sensitive cons...
Jan 16, 2025This vulnerability in IBM MQ Appliance web console allows authenticated users to cause denial-of-service when trace functionality is enabled. It occur...
Dec 19, 2024A directory listing vulnerability in Kashipara E-Learning Management System v1.0 allows remote attackers to browse sensitive files and directories via...
Dec 9, 2024Firepad versions through 1.5.11 allow unauthorized access to document content and edit history when an attacker knows the pad ID. This affects users o...
Dec 4, 2024An out-of-bounds read vulnerability in libfluid's libfluid_msg module allows attackers to read memory beyond intended boundaries when processing OpenF...
Sep 18, 2024CVE-2024-42477 is a global buffer overflow vulnerability in llama.cpp's rpc_tensor structure that can lead to memory data leakage. This affects users ...
Aug 12, 2024This vulnerability allows unauthenticated attackers with network access via HTTP to read sensitive data from Oracle iStore, part of Oracle E-Business ...
Jul 16, 2024This CVE describes an out-of-bounds read vulnerability in Schneider Electric devices that allows attackers to cause denial of service of the web inter...
Jun 12, 2024CVE-2024-36124 is an out-of-bounds read vulnerability in the iq80 Snappy compression library that occurs during decompression of certain data. This ca...
Jun 3, 2024An out-of-bounds read vulnerability in Malwarebytes disassembling utilities can cause application crashes and denial of service. This affects Malwareb...
Aug 14, 2025This vulnerability allows a privileged attacker to perform unauthorized DMA reads from invalid DRAM addresses to SRAM on AMD systems with affected PMF...
Aug 13, 2024This CVE describes an out-of-bounds read vulnerability in Android's baseband firmware that could allow local information disclosure. Attackers could p...
Mar 10, 2025A permissions vulnerability in Apple operating systems allows applications to read arbitrary file metadata without proper authorization. This affects ...
Mar 31, 2025An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory data. Th...
Jan 2, 2026An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory data. Th...
Jan 2, 2026An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory contents...
Jan 2, 2026Sharp and Toshiba Tec multifunction printers (MFPs) have a web interface vulnerability where specially crafted HTTP requests can trigger an out-of-bou...
Oct 25, 2024This vulnerability in MediaTek wlan drivers allows remote attackers to read memory beyond intended boundaries due to improper input validation. It cou...
Oct 7, 2024NVIDIA Triton Inference Server has an out-of-bounds read vulnerability where users can release shared memory regions while they're in use. This could ...
Oct 1, 2024This CVE describes an address read vulnerability (out-of-bounds read) in the HDC module that could allow attackers to read sensitive memory contents. ...
Feb 6, 2026This vulnerability in VLC media player allows an out-of-bounds read and denial of service when processing a specially crafted MMS server response. Att...
Jan 16, 2026This vulnerability in Thunderbird and Firefox allows attackers to trigger undefined behavior through XPath parsing, potentially leading to out-of-boun...
Apr 29, 2025About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,950 CVEs classified as CWE-125, with 214 rated critical and 1,182 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free