CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,715
Total CVEs
150
Critical
1,017
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 87
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,715)

CVE-2018-20313
8.1

This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyPreviewAction function that can lead to stack-based buffer ove...

Jan 7, 2021
CVE-2018-20310
8.1

This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyDoAction function that can lead to stack-based buffer overflow...

Jan 7, 2021
CVE-2018-20312
8.1

This vulnerability in Foxit Reader and PhantomPDF involves a race condition in the proxyDoAction function that can lead to stack-based buffer overflow...

Jan 7, 2021
CVE-2024-41595
8.0

DrayTek Vigor310 devices through firmware version 4.3.2.6 contain buffer overflow vulnerabilities in .cgi pages due to missing bounds checks. This all...

Oct 3, 2024
CVE-2023-21477
7.9

This vulnerability allows local attackers to read protected data from Samsung device memory due to a buffer boundary error in the TIGERF trustlet. It ...

Sep 3, 2025
CVE-2024-36502
7.9

An out-of-bounds read vulnerability in Huawei audio modules could allow attackers to cause denial of service conditions. This affects Huawei consumer ...

Jun 14, 2024
CVE-2026-2664
7.8

An out-of-bounds read vulnerability in the grpcfuse kernel module in Docker Desktop's Linux VM allows local attackers to write to /proc/docker entries...

Feb 24, 2026
CVE-2026-21345
7.8

CVE-2026-21345 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...

Feb 10, 2026
CVE-2026-21343
7.8

Substance3D Stager versions 3.1.6 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this...

Feb 10, 2026
CVE-2026-21324
7.8

CVE-2026-21324 is an out-of-bounds read vulnerability in Adobe After Effects that could allow an attacker to execute arbitrary code in the context of ...

Feb 10, 2026
CVE-2026-21325
7.8

CVE-2026-21325 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...

Feb 10, 2026
CVE-2026-21322
7.8

CVE-2026-21322 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...

Feb 10, 2026
CVE-2026-23720
7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

Feb 10, 2026
CVE-2026-23716
7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

Feb 10, 2026
CVE-2026-23717
7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

Feb 10, 2026
CVE-2026-23718
7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

Feb 10, 2026
CVE-2026-24873
7.8

An out-of-bounds read vulnerability in Rinnegatamante's lpp-vita software allows attackers to read memory beyond allocated buffers. This affects PlayS...

Jan 27, 2026
CVE-2026-20946
7.8

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Users who...

Jan 13, 2026
CVE-2025-14401
7.8

CVE-2025-14401 is an out-of-bounds read vulnerability in PDFsam Enhanced that can lead to remote code execution when users open malicious PDF files or...

Dec 23, 2025
CVE-2025-64462
7.8

An out-of-bounds read vulnerability in NI LabVIEW's LVResFile::RGetMemFileHandle() function when parsing corrupted VI files could lead to information ...

Dec 18, 2025
CVE-2025-64463
7.8

An out-of-bounds read vulnerability in NI LabVIEW's LVResource::DetachResource() function when parsing corrupted VI files could lead to information di...

Dec 18, 2025
CVE-2025-64464
7.8

An out-of-bounds read vulnerability in NI LabVIEW's lvre!VisaWriteFromFile() function when parsing corrupted VI files could lead to information disclo...

Dec 18, 2025
CVE-2025-64465
7.8

This vulnerability allows attackers to read memory outside intended boundaries when a user opens a specially crafted VI file in NI LabVIEW. Successful...

Dec 18, 2025
CVE-2025-64466
7.8

An out-of-bounds read vulnerability in NI LabVIEW's lvre!ExecPostedProcRecPost() function when parsing corrupted VI files could lead to information di...

Dec 18, 2025
CVE-2025-64467
7.8

An out-of-bounds read vulnerability in NI LabVIEW's LVResFile::FindRsrcListEntry() function when parsing corrupted VI files could allow information di...

Dec 18, 2025
CVE-2025-9453
7.8

This CVE describes an Out-of-Bounds Read vulnerability in Autodesk products when parsing malicious PRT files. Attackers can exploit this to crash appl...

Dec 16, 2025
CVE-2025-9454
7.8

CVE-2025-9454 is an out-of-bounds read vulnerability in Autodesk products that parse PRT files. Attackers can exploit this to crash applications, read...

Dec 16, 2025
CVE-2025-9455
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious CATPRODUCT files. Successful explo...

Dec 16, 2025
CVE-2025-9459
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious SLDPRT files. Successful exploitat...

Dec 16, 2025
CVE-2025-9460
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious SLDPRT files. Successful exploitat...

Dec 16, 2025
CVE-2025-14593
7.8

This vulnerability allows attackers to craft malicious CATPART files that trigger an out-of-bounds read when opened in affected Autodesk products. Suc...

Dec 16, 2025
CVE-2025-10883
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk products when processing malicious CATPRODUCT files. Successful explo...

Dec 16, 2025
CVE-2025-36918
7.8

This vulnerability allows local attackers to read memory beyond intended boundaries in Android's aoc_service component, potentially leading to privile...

Dec 11, 2025
CVE-2025-64899
7.8

This CVE describes an out-of-bounds read vulnerability in Adobe Acrobat Reader that could allow an attacker to execute arbitrary code in the context o...

Dec 9, 2025
CVE-2025-55233
7.8

This vulnerability allows an authorized attacker to perform an out-of-bounds read in Windows Projected File System, potentially leading to local privi...

Dec 9, 2025
CVE-2025-48596
7.8

This vulnerability in Android's Parcel.cpp allows an out-of-bounds read due to missing bounds checking. It enables local privilege escalation without ...

Dec 8, 2025
CVE-2025-40936
7.8

An out-of-bounds read vulnerability in the PS/IGES Parasolid Translator Component allows attackers to crash applications or execute arbitrary code by ...

Nov 17, 2025
CVE-2025-61833
7.8

CVE-2025-61833 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...

Nov 11, 2025
CVE-2025-61839
7.8

Format Plugins versions 1.1.1 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could exploit this to ...

Nov 11, 2025
CVE-2025-60727
7.8

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially leading to information disclosure or ...

Nov 11, 2025
CVE-2025-60709
7.8

This vulnerability allows an authorized attacker with local access to exploit an out-of-bounds read in the Windows Common Log File System Driver to el...

Nov 11, 2025
CVE-2025-43386
7.8

An out-of-bounds memory access vulnerability in Apple's media file processing allows malicious media files to cause application crashes or memory corr...

Nov 4, 2025
CVE-2025-43361
7.8

This CVE-2025-43361 is an out-of-bounds read vulnerability in Apple operating systems that allows malicious applications to read kernel memory. It aff...

Nov 4, 2025
CVE-2025-61805
7.8

CVE-2025-61805 is an out-of-bounds read vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious fi...

Oct 14, 2025
CVE-2025-61798
7.8

Adobe Dimension versions 4.1.4 and earlier contain an out-of-bounds read vulnerability when processing malicious files. An attacker could exploit this...

Oct 14, 2025
CVE-2025-55339
7.8

This vulnerability allows an authenticated attacker to read memory outside intended bounds in Windows NDIS (Network Driver Interface Specification), p...

Oct 14, 2025
CVE-2025-40811
7.8

An out-of-bounds read vulnerability in Solid Edge SE2024 and SE2025 allows attackers to crash the application or execute arbitrary code by tricking us...

Oct 14, 2025
CVE-2025-61862
7.8

An out-of-bounds read vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to read memory beyond allocated buffers when processing specially c...

Oct 10, 2025
CVE-2025-61860
7.8

An out-of-bounds read vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to cause information disclosure, system crashes, or arbitrary code ...

Oct 10, 2025
CVE-2025-61691
7.8

VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability that can lead to arbitrary code execution when processing specially craf...

Oct 2, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free