CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,952
Total CVEs
215
Critical
1,183
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
110
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 181
3 Google 169
4 Apple 126
5 Microsoft 113
6 Debian 113
7 Fedoraproject 67
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,952)

CVE-2025-51602
4.8

This vulnerability in VLC media player allows an out-of-bounds read and denial of service when processing a specially crafted MMS server response. Att...

Jan 16, 2026
CVE-2025-4087
4.8

This vulnerability in Thunderbird and Firefox allows attackers to trigger undefined behavior through XPath parsing, potentially leading to out-of-boun...

Apr 29, 2025
CVE-2025-21179
4.8

This vulnerability in the DHCP Client Service allows an attacker to cause a denial of service by sending specially crafted DHCP packets. Systems runni...

Feb 11, 2025
CVE-2024-38481
4.8

Dell iDRAC Service Module versions 5.3.0.0 and earlier contain an out-of-bounds read vulnerability that could allow a privileged local attacker to exe...

Aug 1, 2024
CVE-2025-68132
4.6

This vulnerability in EVerest EV charging software allows attackers to crash the process by sending malformed SLIP frames via serial input. It affects...

Jan 21, 2026
CVE-2026-20828
4.6

This vulnerability allows an unauthorized attacker with physical access to a Windows system to read memory beyond intended boundaries through Windows ...

Jan 13, 2026
CVE-2024-38797
4.6

EDK2's HashPeImageByType() function has an out-of-bounds read vulnerability when processing corrupted data pointers and lengths from adjacent network ...

Apr 7, 2025
CVE-2025-20652
4.6

This vulnerability in V5 DA allows an attacker with physical access to read memory beyond intended boundaries, potentially exposing sensitive informat...

Mar 3, 2025
CVE-2025-21215
4.6

CVE-2025-21215 is a Secure Boot security feature bypass vulnerability that allows attackers with physical access or administrative privileges to bypas...

Jan 14, 2025
CVE-2025-23274
4.5

CVE-2025-23274 is an out-of-bounds read vulnerability in NVIDIA's nvJPEG library where specially crafted JPEG images with malicious dimensions can tri...

Sep 24, 2025
CVE-2023-20987
4.5

This vulnerability allows local information disclosure via Bluetooth on Android 13 devices. An attacker with system execution privileges can read memo...

Mar 24, 2023
CVE-2026-20609
4.4

This memory handling vulnerability in Apple operating systems allows processing malicious files to cause denial-of-service or memory disclosure. It af...

Feb 11, 2026
CVE-2025-23345
4.4

This vulnerability in NVIDIA Display Driver's video decoder allows attackers to read memory beyond allocated boundaries. It affects Windows and Linux ...

Oct 23, 2025
CVE-2025-22392
4.4

An out-of-bounds read vulnerability in Intel AMT and Standard Manageability firmware allows privileged users to potentially disclose sensitive informa...

Aug 12, 2025
CVE-2025-21018
4.4

CVE-2025-21018 is an out-of-bounds read vulnerability in Blockchain Keystore that allows local privileged attackers to read memory beyond allocated bo...

Aug 6, 2025
CVE-2025-54637
4.4

This CVE describes an out-of-bounds array access vulnerability in the kernel ambient light module due to insufficient data verification. Successful ex...

Aug 6, 2025
CVE-2024-11679
4.4

A local input validation weakness in the TpmSetup module for legacy Lenovo System x servers allows attackers with elevated privileges to read memory c...

Apr 11, 2025
CVE-2018-9383
4.4

CVE-2018-9383 is an out-of-bounds read vulnerability in Android's ASN.1 BER decoder that could allow local information disclosure. Attackers need syst...

Jan 17, 2025
CVE-2018-9408
4.4

CVE-2018-9408 is an out-of-bounds read vulnerability in Android's GPS subsystem that could allow local information disclosure. Attackers with system e...

Dec 5, 2024
CVE-2024-20116
4.4

This CVE describes an out-of-bounds read vulnerability in cmdq (likely a MediaTek component) that could allow local information disclosure. Attackers ...

Dec 2, 2024
CVE-2024-20122
4.4

This CVE describes an out-of-bounds read vulnerability in the vdec component of MediaTek chipsets, which could allow local information disclosure. Att...

Nov 4, 2024
CVE-2024-20124
4.4

This vulnerability in MediaTek's vdec component allows local attackers with system privileges to read memory beyond intended boundaries, potentially e...

Nov 4, 2024
CVE-2024-20091
4.4

This CVE describes an out-of-bounds read vulnerability in the vdec component of MediaTek chipsets. It allows local information disclosure but requires...

Oct 7, 2024
CVE-2024-20096
4.4

This vulnerability in MediaTek's m4u component allows an attacker with system privileges to read memory beyond allocated bounds, potentially disclosin...

Oct 7, 2024
CVE-2024-6876
4.4

An out-of-bounds read vulnerability in the OSCAT Basic Library used in CODESYS PLC systems allows local unprivileged attackers to read limited interna...

Sep 10, 2024
CVE-2024-27367
4.4

This vulnerability in Samsung Exynos wearable and mobile processors allows attackers to trigger an integer overflow and heap over-read in the slsi_rx_...

Sep 9, 2024
CVE-2024-27364
4.4

A heap over-read vulnerability in Samsung Exynos mobile and wearable processors allows attackers to read memory beyond allocated buffers. This affects...

Sep 9, 2024
CVE-2024-20085
4.4

CVE-2024-20085 is an out-of-bounds read vulnerability in MediaTek power management components that could allow local information disclosure. Attackers...

Sep 2, 2024
CVE-2024-20041
4.4

This CVE describes an out-of-bounds read vulnerability in MediaTek's 'da' component that could allow local information disclosure. Attackers with syst...

Apr 1, 2024
CVE-2023-21048
4.4

This CVE describes an out-of-bounds read vulnerability in the Android kernel's nan.cpp component. It could allow local information disclosure to attac...

Mar 24, 2023
CVE-2023-21014
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp that could allow local information disclosure. Attackers with system...

Mar 24, 2023
CVE-2023-21032
4.4

This CVE describes a heap buffer overflow vulnerability in Android's Flattened Device Tree (FDT) implementation that could allow local information dis...

Mar 24, 2023
CVE-2023-21039
4.4

This CVE describes an out-of-bounds read vulnerability in Android's dumpstate component that could allow local information disclosure. Attackers with ...

Mar 24, 2023
CVE-2023-20991
4.4

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth Low Energy (BLE) scanner component. It allows local information disclosu...

Mar 24, 2023
CVE-2023-21006
4.4

This vulnerability allows local information disclosure on Android 13 devices through an out-of-bounds read in the p2p_iface.cpp component. Attackers w...

Mar 24, 2023
CVE-2023-21008
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp that could allow local information disclosure. It affects Android 13...

Mar 24, 2023
CVE-2023-21010
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp that could allow local information disclosure. It affects Android 13...

Mar 24, 2023
CVE-2023-21012
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp component. It allows local information disclosure when exploited wit...

Mar 24, 2023
CVE-2023-20977
4.4

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth Low Energy (BLE) stack that could allow local information disclosure. It...

Mar 24, 2023
CVE-2023-20982
4.4

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth stack that could allow local information disclosure. Attackers with syst...

Mar 24, 2023
CVE-2023-20984
4.4

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth subsystem that could allow local information disclosure. Attackers with ...

Mar 24, 2023
CVE-2023-20989
4.4

This CVE describes an out-of-bounds read vulnerability in Android's Bluetooth Low Energy (BLE) stack that could allow local information disclosure. At...

Mar 24, 2023
CVE-2023-20969
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp that could allow local information disclosure. It affects Android 13...

Mar 24, 2023
CVE-2025-46316
4.3

An out-of-bounds read vulnerability in Apple Pages document processing could allow an attacker to cause unexpected termination or disclose process mem...

Jan 28, 2026
CVE-2026-20936
4.3

This vulnerability is an out-of-bounds read in Windows NDIS (Network Driver Interface Specification) that allows an authorized attacker with physical ...

Jan 13, 2026
CVE-2025-58479
4.3

An out-of-bounds read vulnerability in libimagecodec.quram.so allows remote attackers to access memory beyond allocated boundaries. This affects Samsu...

Dec 2, 2025
CVE-2025-9479
4.3

An out-of-bounds read vulnerability in Chrome's V8 JavaScript engine allows remote attackers to potentially exploit heap corruption via malicious HTML...

Nov 14, 2025
CVE-2024-11920
4.3

This vulnerability in Google Chrome's Dawn component on macOS allows attackers to trigger out-of-bounds memory access via malicious HTML pages. It aff...

Nov 14, 2025
CVE-2025-60728
4.3

This vulnerability in Microsoft Office Excel involves an untrusted pointer dereference that could allow an attacker to read sensitive memory contents....

Nov 11, 2025
CVE-2025-12443
4.3

This vulnerability allows a remote attacker to read memory outside the intended buffer boundaries in Chrome's WebXR implementation. Attackers could po...

Nov 10, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,952 CVEs classified as CWE-125, with 215 rated critical and 1,183 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free