CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,711
Total CVEs
150
Critical
1,013
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 86
6 Debian 81
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,711)

CVE-2026-0899
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to memory cor...

Jan 20, 2026
CVE-2025-14766
8.8

This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds read/write in Chrome's V8 JavaScript engine. Attackers can...

Dec 16, 2025
CVE-2025-12725
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory writes via a crafted HTML page targeting Chrome's WebGPU implementation on ...

Nov 10, 2025
CVE-2025-12036
8.8

This vulnerability allows a remote attacker to perform out-of-bounds memory access in Chrome's V8 JavaScript engine by tricking users into visiting a ...

Nov 6, 2025
CVE-2025-49687
8.8

This vulnerability allows an authorized attacker to perform an out-of-bounds read in Microsoft Input Method Editor (IME), potentially leading to local...

Jul 8, 2025
CVE-2025-2073
8.8

This vulnerability allows a local attacker with low privileges to trigger an out-of-bounds read in the netfilter/ipset subsystem of the Linux kernel. ...

Apr 16, 2025
CVE-2025-2137
8.8

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's V8 JavaScript engine by tricking users into visitin...

Mar 10, 2025
CVE-2025-1918
8.8

This vulnerability allows a remote attacker to read memory outside the intended buffer boundaries in Chrome's PDF rendering engine (PDFium) by trickin...

Mar 5, 2025
CVE-2025-1919
8.8

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's media component via a specially crafted HTML page. ...

Mar 5, 2025
CVE-2025-1914
8.8

This vulnerability allows a remote attacker to read memory outside the intended bounds of V8's JavaScript engine in Chrome. Attackers could potentiall...

Mar 5, 2025
CVE-2025-0906
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing JB2 files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0907
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing JB2 files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0908
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing U3D files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0909
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing XPS files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0911
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing U3D files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0901
8.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...

Feb 11, 2025
CVE-2025-0902
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing XPS files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0904
8.8

PDF-XChange Editor contains an out-of-bounds read vulnerability when parsing XPS files, allowing attackers to disclose sensitive information from memo...

Feb 11, 2025
CVE-2025-0905
8.8

This vulnerability in PDF-XChange Editor allows remote attackers to disclose sensitive information by exploiting an out-of-bounds read flaw in JB2 fil...

Feb 11, 2025
CVE-2025-0437
8.8

This vulnerability allows a remote attacker to trigger an out-of-bounds read in Chrome's Metrics component via a crafted HTML page, potentially leadin...

Jan 15, 2025
CVE-2024-30068
8.8

This Windows kernel vulnerability allows attackers to gain SYSTEM-level privileges by exploiting improper memory handling. It affects all Windows syst...

Jun 11, 2024
CVE-2024-5159
8.8

A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome allows remote attackers to perform out-of-bounds ...

May 22, 2024
CVE-2024-34200
8.8

This CVE describes a stack buffer overflow vulnerability in the setIpQosRules function of TOTOLINK CPE CP450 routers. Attackers can exploit this to ex...

May 14, 2024
CVE-2024-3854
8.8

This vulnerability in Mozilla's JavaScript JIT compiler incorrectly optimizes switch statements, leading to out-of-bounds memory reads. It affects Fir...

Apr 16, 2024
CVE-2024-28938
8.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially ...

Apr 9, 2024
CVE-2024-3156
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to perform out-of-bounds memory access via malicious HTML pages, potentially lead...

Apr 6, 2024
CVE-2023-4072
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's WebGL implementation, potentially leading to heap corru...

Aug 3, 2023
CVE-2022-24353
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on TP-Link AC1750 routers without authentication. The flaw e...

Mar 28, 2023
CVE-2023-0698
8.8

This vulnerability allows a remote attacker to read memory outside the intended bounds in Chrome's WebRTC component via a malicious HTML page. It affe...

Feb 7, 2023
CVE-2022-28661
8.8

This vulnerability in Simcenter Femap allows remote code execution via specially crafted .NEU files due to an out-of-bounds read. It affects all versi...

Apr 12, 2022
CVE-2022-24971
8.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Feb 18, 2022
CVE-2021-4100
8.8

This vulnerability in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome allows a remote attacker to potentially exploit heap corruption thr...

Feb 11, 2022
CVE-2022-23594
8.8

This vulnerability in TensorFlow's TFG dialect allows attackers to cause crashes or potentially execute arbitrary code by manipulating SavedModel file...

Feb 4, 2022
CVE-2022-23560
8.8

This vulnerability in TensorFlow allows attackers to craft malicious TFLite models that can read and write memory outside of allocated arrays during s...

Feb 4, 2022
CVE-2021-37972
8.8

This vulnerability is an out-of-bounds read in libjpeg-turbo in Google Chrome that could allow a remote attacker to exploit heap corruption via a craf...

Oct 8, 2021
CVE-2021-1867
8.8

CVE-2021-1867 is an out-of-bounds read vulnerability in Apple's iOS, iPadOS, and macOS that allows malicious applications to execute arbitrary code wi...

Sep 8, 2021
CVE-2021-30953
8.8

This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into visiting malicious web pages. It affect...

Aug 24, 2021
CVE-2021-29988
8.8

This vulnerability in Firefox and Thunderbird involves incorrect handling of inline list-item elements as block elements, leading to out-of-bounds mem...

Aug 17, 2021
CVE-2020-19499
8.8

This vulnerability in libheif's Box_iref::get_references function allows attackers to trigger an invalid memory read, potentially causing denial of se...

Jul 21, 2021
CVE-2021-1792
8.8

CVE-2021-1792 is an out-of-bounds read vulnerability in Apple operating systems that could allow remote attackers to execute arbitrary code. This affe...

Apr 2, 2021
CVE-2020-26996
8.8

This vulnerability allows remote code execution through memory corruption when parsing malicious CG4 files in Siemens JT2Go and Teamcenter Visualizati...

Jan 12, 2021
CVE-2021-21463
8.8

CVE-2021-21463 is a vulnerability in SAP 3D Visual Enterprise Viewer version 9 that allows attackers to crash the application by tricking users into o...

Jan 12, 2021
CVE-2025-20152
8.6

An unauthenticated remote attacker can send specially crafted RADIUS authentication requests to cause Cisco Identity Services Engine (ISE) to reload, ...

May 21, 2025
CVE-2024-36114
8.6

Aircompressor library versions before 0.27 contain out-of-bounds memory access vulnerabilities in all decompressor implementations (LZ4, LZO, Snappy, ...

May 29, 2024
CVE-2023-50927
8.6

This vulnerability allows attackers to trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol in Contiki-NG IoT operating syst...

Feb 14, 2024
CVE-2025-8067
8.5

CVE-2025-8067 is an out-of-bounds read vulnerability in the Udisks daemon that allows unprivileged local users to create loop devices with negative in...

Aug 28, 2025
CVE-2026-20944
8.4

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Office Word, potentially leading to arbitrary code execu...

Jan 13, 2026
CVE-2025-24311
8.4

An out-of-bounds read vulnerability in Dell ControlVault3 and ControlVault3 Plus allows attackers to leak sensitive information via specially crafted ...

Jun 13, 2025
CVE-2024-27529
8.4

CVE-2024-27529 is a memory leak vulnerability in wasm3's Read_utf8 function that allows attackers to cause denial of service through resource exhausti...

Nov 8, 2024
CVE-2024-41928
8.4

A buffer overflow vulnerability in bhyve's userspace process allows malicious software running in a guest virtual machine to execute arbitrary code on...

Sep 5, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,711 CVEs classified as CWE-125, with 150 rated critical and 1,013 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free