CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,715)
This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyPreviewAction function that can lead to stack-based buffer ove...
Jan 7, 2021This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyDoAction function that can lead to stack-based buffer overflow...
Jan 7, 2021This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyDoAction function that can lead to stack-based buffer overflow...
Jan 7, 2021DrayTek Vigor310 devices through firmware version 4.3.2.6 contain buffer overflow vulnerabilities in .cgi pages due to missing bounds checks. This all...
Oct 3, 2024This vulnerability allows local attackers to read protected data from Samsung device memory due to a buffer boundary error in the TIGERF trustlet. It ...
Sep 3, 2025An out-of-bounds read vulnerability in Huawei audio modules could allow attackers to cause denial of service conditions. This affects Huawei consumer ...
Jun 14, 2024An out-of-bounds read vulnerability in the grpcfuse kernel module in Docker Desktop's Linux VM allows local attackers to write to /proc/docker entries...
Feb 24, 2026CVE-2026-21345 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...
Feb 10, 2026Substance3D Stager versions 3.1.6 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this...
Feb 10, 2026CVE-2026-21324 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to execute arbitrary code in the context of ...
Feb 10, 2026CVE-2026-21325 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...
Feb 10, 2026CVE-2026-21322 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...
Feb 10, 2026An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...
Feb 10, 2026An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...
Feb 10, 2026An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...
Feb 10, 2026An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...
Feb 10, 2026An out-of-bounds read vulnerability in Rinnegatamante's lpp-vita software allows attackers to read memory beyond allocated buffers. This affects PlayS...
Jan 27, 2026This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Users who...
Jan 13, 2026CVE-2025-14401 is an out-of-bounds read vulnerability in PDFsam Enhanced that can lead to remote code execution when users open malicious PDF files or...
Dec 23, 2025An out-of-bounds read vulnerability in NI LabVIEW's LVResFile::RGetMemFileHandle() function when parsing corrupted VI files could lead to information ...
Dec 18, 2025An out-of-bounds read vulnerability in NI LabVIEW's LVResource::DetachResource() function when parsing corrupted VI files could lead to information di...
Dec 18, 2025An out-of-bounds read vulnerability in NI LabVIEW's lvre!VisaWriteFromFile() function when parsing corrupted VI files could lead to information disclo...
Dec 18, 2025This vulnerability allows attackers to read memory outside intended boundaries when a user opens a specially crafted VI file in NI LabVIEW. Successful...
Dec 18, 2025An out-of-bounds read vulnerability in NI LabVIEW's lvre!ExecPostedProcRecPost() function when parsing corrupted VI files could lead to information di...
Dec 18, 2025An out-of-bounds read vulnerability in NI LabVIEW's LVResFile::FindRsrcListEntry() function when parsing corrupted VI files could allow information di...
Dec 18, 2025This CVE describes an Out-of-Bounds Read vulnerability in Autodesk products when parsing malicious PRT files. Attackers can exploit this to crash appl...
Dec 16, 2025CVE-2025-9454 is an out-of-bounds read vulnerability in Autodesk products that parse PRT files. Attackers can exploit this to crash applications, read...
Dec 16, 2025This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious CATPRODUCT files. Successful explo...
Dec 16, 2025This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious SLDPRT files. Successful exploitat...
Dec 16, 2025This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious SLDPRT files. Successful exploitat...
Dec 16, 2025This vulnerability allows attackers to craft malicious CATPART files that trigger an out-of-bounds read when opened in affected Autodesk products. Suc...
Dec 16, 2025This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious CATPRODUCT files. Successful explo...
Dec 16, 2025This vulnerability allows local attackers to read memory beyond intended boundaries in Android's aoc_service component, potentially leading to privile...
Dec 11, 2025This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to execute arbitrary code in the context o...
Dec 9, 2025This vulnerability allows an authorized attacker to perform an out-of-bounds read in Windows Projected File System, potentially leading to local privi...
Dec 9, 2025This vulnerability in Android's Parcel.cpp allows an out-of-bounds read due to missing bounds checking. It enables local privilege escalation without ...
Dec 8, 2025An out-of-bounds read vulnerability in the PS/IGES Parasolid Translator Component allows attackers to crash applications or execute arbitrary code by ...
Nov 17, 2025CVE-2025-61833 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...
Nov 11, 2025Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this to ...
Nov 11, 2025This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially leading to information disclosure or ...
Nov 11, 2025This vulnerability allows an authorized attacker with local access to exploit an out-of-bounds read in the Windows Common Log File System Driver to el...
Nov 11, 2025An out-of-bounds memory access vulnerability in Apple's media file processing allows malicious media files to cause application crashes or memory corr...
Nov 4, 2025This CVE-2025-43361 is an out-of-bounds read vulnerability in Apple operating systems that allows malicious applications to read kernel memory. It aff...
Nov 4, 2025CVE-2025-61805 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...
Oct 14, 2025Adobe Dimension versions 4.1.4 and earlier contain an out-of-bounds read vulnerability when processing malicious files. An attacker could exploit this...
Oct 14, 2025This vulnerability allows an authenticated attacker to read memory outside intended bounds in Windows NDIS (Network Driver Interface Specification), p...
Oct 14, 2025An out-of-bounds read vulnerability in Solid Edge SE2024 and SE2025 allows attackers to crash the application or execute arbitrary code by tricking us...
Oct 14, 2025An out-of-bounds read vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to read memory beyond allocated buffers when processing specially c...
Oct 10, 2025An out-of-bounds read vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to cause information disclosure, system crashes, or arbitrary code ...
Oct 10, 2025VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability that can lead to arbitrary code execution when processing specially craf...
Oct 2, 2025About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free