CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,960
Total CVEs
223
Critical
1,183
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
110
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 303
2 Adobe 181
3 Google 169
4 Apple 126
5 Debian 116
6 Microsoft 113
7 Fedoraproject 69
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,960)

CVE-2023-20969
4.4

This CVE describes an out-of-bounds read vulnerability in Android's p2p_iface.cpp that could allow local information disclosure. It affects Android 13...

Mar 24, 2023
CVE-2025-46316
4.3

An out-of-bounds read vulnerability in Apple Pages document processing could allow an attacker to cause unexpected termination or disclose process mem...

Jan 28, 2026
CVE-2026-20936
4.3

This vulnerability is an out-of-bounds read in Windows NDIS (Network Driver Interface Specification) that allows an authorized attacker with physical ...

Jan 13, 2026
CVE-2025-58479
4.3

An out-of-bounds read vulnerability in libimagecodec.quram.so allows remote attackers to access memory beyond allocated boundaries. This affects Samsu...

Dec 2, 2025
CVE-2025-9479
4.3

An out-of-bounds read vulnerability in Chrome's V8 JavaScript engine allows remote attackers to potentially exploit heap corruption via malicious HTML...

Nov 14, 2025
CVE-2024-11920
4.3

This vulnerability in Google Chrome's Dawn component on macOS allows attackers to trigger out-of-bounds memory access via malicious HTML pages. It aff...

Nov 14, 2025
CVE-2025-60728
4.3

This vulnerability in Microsoft Office Excel involves an untrusted pointer dereference that could allow an attacker to read sensitive memory contents....

Nov 11, 2025
CVE-2025-12443
4.3

This vulnerability allows a remote attacker to read memory outside the intended buffer boundaries in Chrome's WebXR implementation. Attackers could po...

Nov 10, 2025
CVE-2025-12441
4.3

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's V8 JavaScript engine via a malicious HTML page. It ...

Nov 10, 2025
CVE-2025-21074
4.3

An out-of-bounds read vulnerability in Samsung's libimagecodec.quram.so library allows remote attackers to access memory beyond allocated boundaries. ...

Nov 5, 2025
CVE-2025-43383
4.3

This CVE describes an out-of-bounds memory access vulnerability in Apple's media file processing. Attackers can craft malicious media files that cause...

Nov 4, 2025
CVE-2025-43384
4.3

This CVE describes an out-of-bounds memory access vulnerability in Apple's media file processing. Attackers can craft malicious media files that cause...

Nov 4, 2025
CVE-2025-43385
4.3

This CVE describes an out-of-bounds memory access vulnerability in Apple's media file processing components. Attackers can craft malicious media files...

Nov 4, 2025
CVE-2025-21055
4.3

This vulnerability in Samsung's libimagecodec.quram.so library allows remote attackers to read and write beyond allocated memory boundaries. It affect...

Oct 10, 2025
CVE-2025-40578
4.3

A denial-of-service vulnerability in Siemens SCALANCE LPE9403 devices allows unauthenticated remote attackers to crash the dcpd process by sending mul...

May 13, 2025
CVE-2025-31354
4.3

This vulnerability in Subnet Solutions PowerSYSTEM Center's SMTPS notification service allows attackers to cause denial of service through excessive C...

Apr 11, 2025
CVE-2025-24055
4.3

An out-of-bounds read vulnerability in the Windows USB Video Driver allows an authorized attacker with physical access to read sensitive information f...

Mar 11, 2025
CVE-2025-20640
4.3

This vulnerability in MediaTek DA software allows an attacker with physical access to read memory beyond intended boundaries, potentially exposing sen...

Feb 3, 2025
CVE-2025-21530
4.3

This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows authenticated attackers with low privileges to read sensitive data they shouldn'...

Jan 21, 2025
CVE-2024-56378
4.3

CVE-2024-56378 is an out-of-bounds read vulnerability in Poppler's JBIG2Stream.cc that could allow an attacker to read sensitive memory data from the ...

Dec 23, 2024
CVE-2024-49099
4.3

This vulnerability in Windows Wireless Wide Area Network Service (WwanSvc) allows an authenticated attacker to read sensitive information from system ...

Dec 12, 2024
CVE-2024-9758
4.3

This vulnerability in Tungsten Automation Power PDF allows attackers to read sensitive information from memory when users open malicious PDF files. Th...

Nov 22, 2024
CVE-2024-9143
4.3

This OpenSSL vulnerability allows out-of-bounds memory reads/writes when using low-level GF(2^m) elliptic curve APIs with untrusted explicit field pol...

Oct 16, 2024
CVE-2024-40630
4.3

This vulnerability in OpenImageIO's HEIF image processing functionality allows information disclosure when processing malicious HEIF files. It affects...

Jul 15, 2024
CVE-2024-32915
4.3

This CVE describes an out-of-bounds read vulnerability in the CellInfoListParserV2::FillCellInfo() function of protocolnetadapter.cpp in Android's bas...

Jun 13, 2024
CVE-2024-24583
4.3

This vulnerability allows an attacker to cause an out-of-bounds read in libigl's readMSH function by providing a specially crafted .msh file. This cou...

May 28, 2024
CVE-2025-58476
4.2

An out-of-bounds read vulnerability in Samsung device bootloaders allows physical attackers to read memory beyond intended boundaries. This affects Sa...

Dec 2, 2025
CVE-2026-27798
4.0

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a heap buffer over-read vulnerability when processing images with small dimensions using ...

Feb 26, 2026
CVE-2025-43205
4.0

This CVE describes an out-of-bounds memory access vulnerability in Apple operating systems that could allow an app to bypass Address Space Layout Rand...

Nov 12, 2025
CVE-2025-21067
4.0

This vulnerability allows local attackers to read memory outside the intended buffer boundaries in Samsung Notes. It affects users of Samsung Notes ve...

Oct 10, 2025
CVE-2025-21068
4.0

This vulnerability allows local attackers to read memory outside the intended bounds when processing image data in Samsung Notes. It affects users of ...

Oct 10, 2025
CVE-2025-21069
4.0

This vulnerability allows local attackers to read memory outside the intended bounds when parsing image data in Samsung Notes. It affects users of Sam...

Oct 10, 2025
CVE-2025-21066
4.0

An out-of-bounds read vulnerability in Samsung Notes' SPI decoder allows local attackers to access memory beyond intended boundaries. This affects Sam...

Oct 10, 2025
CVE-2025-21054
4.0

This vulnerability allows local attackers to read out-of-bounds memory during JPEG header parsing in Samsung's libpadm.so library. It affects Samsung ...

Oct 10, 2025
CVE-2025-43226
4.0

This vulnerability allows an attacker to read memory outside the intended buffer when processing a malicious image. It affects Apple devices running v...

Jul 30, 2025
CVE-2025-20992
4.0

This vulnerability allows local attackers to read out-of-bounds memory in Samsung's camera library on affected devices. It affects Samsung devices run...

Jun 4, 2025
CVE-2025-32460
4.0

This vulnerability is a heap-based buffer over-read in GraphicsMagick's JXL image decoder that occurs when processing specially crafted JPEG XL files....

Apr 9, 2025
CVE-2023-4458
4.0

CVE-2023-4458 is an out-of-bounds read vulnerability in the Linux kernel's ksmbd module when parsing extended attributes. This allows attackers to rea...

Nov 14, 2024
CVE-2024-20505
4.0

An out-of-bounds read vulnerability in ClamAV's PDF parsing module allows remote attackers to cause denial of service by submitting crafted PDF files....

Sep 4, 2024
CVE-2024-34658
4.0

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to bypass ASLR (Address Space Layout Randomization). This affects Samsung ...

Sep 4, 2024
CVE-2024-34632
4.0

An out-of-bounds read vulnerability in Samsung Notes' UUID parsing allows a local attacker to read unauthorized memory. This affects Samsung Notes ver...

Aug 7, 2024
CVE-2024-34634
4.0

An out-of-bounds read vulnerability in Samsung Notes allows a local attacker to access unauthorized memory when parsing connected object lists. This a...

Aug 7, 2024
CVE-2026-22885
3.7

A memory leak vulnerability in EnOcean SmartServer IoT versions 4.60.009 and prior allows remote attackers to send specially crafted LON IP-852 manage...

Feb 20, 2026
CVE-2025-57812
3.7

This vulnerability allows an attacker to trigger out-of-bounds memory read/write operations by submitting a malicious TIFF file through a print job wi...

Nov 12, 2025
CVE-2025-14408
3.3

This vulnerability in Soda PDF Desktop allows attackers to read memory beyond allocated boundaries when parsing malicious PDF files, potentially discl...

Dec 23, 2025
CVE-2025-55307
3.3

This vulnerability in Foxit PDF software allows attackers to trigger an out-of-bounds read by tricking users into opening malicious PDF files containi...

Dec 11, 2025
CVE-2025-53470
3.1

An out-of-bounds read vulnerability in Apache NimBLE's HCI H4 driver allows a malicious or malfunctioning Bluetooth controller to trigger invalid memo...

Jan 10, 2026
CVE-2025-14055
N/A

An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows attackers to read beyond allocated memory buffers via special...

Feb 20, 2026
CVE-2025-65081
N/A

An out-of-bounds read vulnerability in the Postscript interpreter of Lexmark devices allows attackers to execute arbitrary code as an unprivileged use...

Feb 3, 2026
CVE-2026-24826
N/A

This CVE describes multiple memory safety vulnerabilities in cadaver turso3d software, including out-of-bounds writes, divide-by-zero errors, and unin...

Jan 27, 2026

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,960 CVEs classified as CWE-125, with 223 rated critical and 1,183 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free