CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,715
Total CVEs
150
Critical
1,017
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 87
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,715)

CVE-2025-7977
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious LI files or visiting malicious web pages...

Sep 17, 2025
CVE-2025-54262
7.8

Substance3D Stager versions 3.1.3 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. This could allow an attacker t...

Sep 16, 2025
CVE-2025-54260
7.8

Substance3D Modeler versions 1.22.2 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. This could allow an attacker...

Sep 9, 2025
CVE-2025-54902
7.8

An out-of-bounds read vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into op...

Sep 9, 2025
CVE-2025-54898
7.8

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Attackers...

Sep 9, 2025
CVE-2025-9326
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw ...

Sep 2, 2025
CVE-2025-9328
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw ...

Sep 2, 2025
CVE-2025-41392
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing AR files in Ashlar-Vellum CAD software....

Aug 18, 2025
CVE-2025-5046
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk AutoCAD when processing malicious DGN files. Attackers could crash th...

Aug 15, 2025
CVE-2025-6635
7.8

CVE-2025-6635 is an out-of-bounds read vulnerability in certain Autodesk products that allows attackers to crash applications, read sensitive memory, ...

Jul 29, 2025
CVE-2025-38375
7.8

This vulnerability in the Linux kernel's virtio-net driver allows an out-of-bound read when processing XDP (eXpress Data Path) packets. Attackers coul...

Jul 25, 2025
CVE-2025-7324
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7322
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7312
7.8

This vulnerability in IrfanView's CADImage plugin allows remote attackers to execute arbitrary code when users open malicious DWG files. Attackers can...

Jul 21, 2025
CVE-2025-7298
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7268
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7262
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7264
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CGM files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7251
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7242
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7247
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-0831
7.8

An out-of-bounds read vulnerability in SOLIDWORKS eDrawings 2025 allows attackers to execute arbitrary code by tricking users into opening malicious J...

Jul 15, 2025
CVE-2025-49689
7.8

An integer overflow vulnerability in Virtual Hard Disk (VHDX) handling allows local attackers to escalate privileges on affected systems. This affects...

Jul 8, 2025
CVE-2025-48816
7.8

An integer overflow vulnerability in the HID class driver allows authenticated attackers to execute arbitrary code with elevated privileges on affecte...

Jul 8, 2025
CVE-2025-47996
7.8

An integer underflow vulnerability in the Windows MBT Transport driver allows authenticated attackers to execute arbitrary code with elevated SYSTEM p...

Jul 8, 2025
CVE-2025-40740
7.8

This vulnerability in Solid Edge SE2025 allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PAR file...

Jul 8, 2025
CVE-2025-6642
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files or visit...

Jun 25, 2025
CVE-2025-32412
7.8

Fuji Electric Smart Editor contains an out-of-bounds read vulnerability (CWE-125) that could allow an attacker to execute arbitrary code on affected s...

Jun 17, 2025
CVE-2025-32716
7.8

CVE-2025-32716 is an out-of-bounds read vulnerability in Windows Media components that allows authenticated attackers to elevate privileges locally. T...

Jun 10, 2025
CVE-2025-5307
7.8

Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability (CWE-125) that allows a local attacker to potentially disclose sensitive i...

May 29, 2025
CVE-2025-47756
7.8

This vulnerability in V-SFT v6.2.5.0 and earlier allows attackers to trigger an out-of-bounds read when opening specially crafted V7 or V8 files. Succ...

May 19, 2025
CVE-2025-47754
7.8

V-SFT v6.2.5.0 and earlier contain an out-of-bounds read vulnerability in the Conv_Macro_Data function. Attackers can exploit this by tricking users i...

May 19, 2025
CVE-2025-30419
7.8

A memory corruption vulnerability in NI Circuit Design Suite's SymbolEditor allows attackers to execute arbitrary code or disclose sensitive informati...

May 15, 2025
CVE-2025-2509
7.8

This vulnerability allows a malicious guest virtual machine to perform out-of-bounds memory reads within the crosvm sandboxed process on ChromeOS. Att...

May 6, 2025
CVE-2025-27741
7.8

This vulnerability is an out-of-bounds read in Windows NTFS that allows a local attacker to read memory they shouldn't access. Attackers can exploit t...

Apr 8, 2025
CVE-2025-27728
7.8

CVE-2025-27728 is an out-of-bounds read vulnerability in Windows Kernel-Mode Drivers that allows authenticated local attackers to read kernel memory a...

Apr 8, 2025
CVE-2025-27483
7.8

This vulnerability is an out-of-bounds read in Windows NTFS that allows a local attacker to read sensitive memory contents and potentially elevate pri...

Apr 8, 2025
CVE-2025-26675
7.8

This vulnerability allows an authorized attacker with local access to exploit an out-of-bounds read in Windows Subsystem for Linux to elevate privileg...

Apr 8, 2025
CVE-2025-21438
7.8

This vulnerability allows memory corruption when a user-space application makes a specific IOCTL call to read board data on Qualcomm chipsets. Attacke...

Apr 7, 2025
CVE-2025-1659
7.8

This vulnerability in Autodesk Navisworks allows attackers to exploit an out-of-bounds read by tricking users into opening a malicious DWFX file, pote...

Apr 1, 2025
CVE-2025-24228
7.8

A buffer overflow vulnerability in macOS allows malicious applications to execute arbitrary code with kernel privileges. This affects macOS Ventura, S...

Mar 31, 2025
CVE-2025-2231
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious RTF files. The fla...

Mar 24, 2025
CVE-2025-1652
7.8

This CVE describes an out-of-bounds read vulnerability in Autodesk AutoCAD when parsing malicious MODEL files. Attackers can exploit this to crash the...

Mar 13, 2025
CVE-2025-1431
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk AutoCAD when processing malicious SLDPRT files. Successful exploitati...

Mar 13, 2025
CVE-2025-1433
7.8

CVE-2025-1433 is an out-of-bounds read vulnerability in Autodesk AutoCAD that allows attackers to craft malicious MODEL files to cause crashes, read s...

Mar 13, 2025
CVE-2025-1428
7.8

This vulnerability allows attackers to craft malicious CATPART files that trigger an out-of-bounds read when opened in Autodesk AutoCAD. Successful ex...

Mar 13, 2025
CVE-2025-2012
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VS files in Ashlar-Vellum Cobalt softwar...

Mar 11, 2025
CVE-2025-24059
7.8

This vulnerability in Windows Common Log File System Driver involves incorrect numeric type conversion that allows authenticated attackers to escalate...

Mar 11, 2025
CVE-2025-27438
7.8

This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...

Mar 11, 2025
CVE-2025-23401
7.8

This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...

Mar 11, 2025

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free