CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,974
Total CVEs
224
Critical
1,196
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
110
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 304
2 Adobe 189
3 Google 169
4 Apple 126
5 Debian 117
6 Microsoft 113
7 Fedoraproject 69
8 Siemens 64
9 Pdf Xchange 58
10 Samsung 51

All Out-of-bounds Read CVEs (1,974)

CVE-2025-32460
4.0

This vulnerability is a heap-based buffer over-read in GraphicsMagick's JXL image decoder that occurs when processing specially crafted JPEG XL files....

Apr 9, 2025
CVE-2023-4458
4.0

CVE-2023-4458 is an out-of-bounds read vulnerability in the Linux kernel's ksmbd module when parsing extended attributes. This allows attackers to rea...

Nov 14, 2024
CVE-2024-20505
4.0

An out-of-bounds read vulnerability in ClamAV's PDF parsing module allows remote attackers to cause denial of service by submitting crafted PDF files....

Sep 4, 2024
CVE-2024-34658
4.0

An out-of-bounds read vulnerability in Samsung Notes allows local attackers to bypass ASLR (Address Space Layout Randomization). This affects Samsung ...

Sep 4, 2024
CVE-2024-34632
4.0

An out-of-bounds read vulnerability in Samsung Notes' UUID parsing allows a local attacker to read unauthorized memory. This affects Samsung Notes ver...

Aug 7, 2024
CVE-2024-34634
4.0

An out-of-bounds read vulnerability in Samsung Notes allows a local attacker to access unauthorized memory when parsing connected object lists. This a...

Aug 7, 2024
CVE-2026-22885
3.7

A memory leak vulnerability in EnOcean SmartServer IoT versions 4.60.009 and prior allows remote attackers to send specially crafted LON IP-852 manage...

Feb 20, 2026
CVE-2025-57812
3.7

This vulnerability allows an attacker to trigger out-of-bounds memory read/write operations by submitting a malicious TIFF file through a print job wi...

Nov 12, 2025
CVE-2025-14408
3.3

This vulnerability in Soda PDF Desktop allows attackers to read memory beyond allocated boundaries when parsing malicious PDF files, potentially discl...

Dec 23, 2025
CVE-2025-55307
3.3

This vulnerability in Foxit PDF software allows attackers to trigger an out-of-bounds read by tricking users into opening malicious PDF files containi...

Dec 11, 2025
CVE-2025-53470
3.1

An out-of-bounds read vulnerability in Apache NimBLE's HCI H4 driver allows a malicious or malfunctioning Bluetooth controller to trigger invalid memo...

Jan 10, 2026
CVE-2025-14055
N/A

An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows attackers to read beyond allocated memory buffers via special...

Feb 20, 2026
CVE-2025-65081
N/A

An out-of-bounds read vulnerability in the Postscript interpreter of Lexmark devices allows attackers to execute arbitrary code as an unprivileged use...

Feb 3, 2026
CVE-2026-24826
N/A

This CVE describes multiple memory safety vulnerabilities in cadaver turso3d software, including out-of-bounds writes, divide-by-zero errors, and unin...

Jan 27, 2026
CVE-2026-24818
N/A

An out-of-bounds read vulnerability in praydog UEVR's Lua parser component could allow attackers to read sensitive memory contents. This affects UEVR ...

Jan 27, 2026
CVE-2026-24820
N/A

An out-of-bounds read vulnerability in WickedEngine's LUA modules (specifically ldebug.C) allows attackers to read memory beyond allocated buffers. Th...

Jan 27, 2026
CVE-2026-24821
N/A

An out-of-bounds read vulnerability in WickedEngine's LUA parser allows attackers to read memory beyond allocated buffers. This affects applications u...

Jan 27, 2026
CVE-2026-24812
N/A

This vulnerability in ROOT's built-in zlib modules (specifically inftrees.C) could allow memory corruption or code execution when processing compresse...

Jan 27, 2026
CVE-2026-24796
N/A

This CVE describes an out-of-bounds read vulnerability in CloverBootloader's Oniguruma regular expression module. An attacker could exploit this to re...

Jan 27, 2026
CVE-2026-22185
N/A

This vulnerability is a heap buffer underflow in OpenLDAP LMDB's mdb_load utility that allows an attacker to cause a denial-of-service by crashing the...

Jan 7, 2026
CVE-2025-11775
N/A

An out-of-bounds read vulnerability in the asComSvc service on ASUS motherboards can be exploited via specially crafted requests, potentially causing ...

Dec 17, 2025
CVE-2025-67721
N/A

CVE-2025-67721 is a memory disclosure vulnerability in Aircompressor Java library where malformed Snappy and LZ4 compressed data can leak previous buf...

Dec 12, 2025
CVE-2025-67749
N/A

This vulnerability in PCSX2 allows specially crafted PlayStation 2 disc images or ELF files to trigger an out-of-bounds memory read. Attackers could p...

Dec 12, 2025
CVE-2025-12183
N/A

This vulnerability in lz4-java library allows remote attackers to cause denial of service and potentially read adjacent memory by sending specially cr...

Nov 28, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,974 CVEs classified as CWE-125, with 224 rated critical and 1,196 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.2.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free