CWE-125: Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

1,715
Total CVEs
150
Critical
1,017
High
7.1
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
97
2025
598
2024
514
2023
198
2022
109

Top Affected Vendors

1 Linux 297
2 Adobe 159
3 Google 149
4 Microsoft 113
5 Apple 87
6 Debian 82
7 Siemens 62
8 Pdf Xchange 58
9 Samsung 51
10 Fedoraproject 38

All Out-of-bounds Read CVEs (1,715)

CVE-2024-57998
7.8

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's Operating Performance Point (OPP) framework. An attacker could potentiall...

Feb 27, 2025
CVE-2022-49261
7.8

A missing bounds check in the Linux kernel's i915 graphics driver vm_access() function allows out-of-bounds memory access. This vulnerability could le...

Feb 26, 2025
CVE-2025-0591
7.8

An out-of-bounds read vulnerability in CX-Programmer allows attackers to read sensitive memory contents or cause application crashes. This affects use...

Feb 17, 2025
CVE-2024-12549
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Tungsten Automation Power P...

Feb 11, 2025
CVE-2024-12550
7.8

This vulnerability in Tungsten Automation Power PDF allows attackers to disclose sensitive information by tricking users into opening malicious JP2 fi...

Feb 11, 2025
CVE-2024-12551
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Tungsten Automation Power P...

Feb 11, 2025
CVE-2025-21383
7.8

This vulnerability in Microsoft Excel allows an attacker to read sensitive information from memory when a specially crafted file is opened. It affects...

Feb 11, 2025
CVE-2025-21687
7.8

This CVE is a Linux kernel vulnerability in the vfio/platform driver where user-supplied count and offset parameters in read/write syscalls are not pr...

Feb 10, 2025
CVE-2018-9464
7.8

CVE-2018-9464 is a local privilege escalation vulnerability in Android that allows attackers to read protected system files without proper permission ...

Jan 18, 2025
CVE-2024-13169
7.8

This vulnerability allows a local authenticated attacker to perform an out-of-bounds read in Ivanti Endpoint Manager (EPM), potentially leading to pri...

Jan 14, 2025
CVE-2024-12751
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Dec 30, 2024
CVE-2024-12212
7.8

CVE-2024-12212 is an out-of-bounds read vulnerability in CSP file parsing that could allow arbitrary code execution. This affects users of Horner Auto...

Dec 13, 2024
CVE-2024-12130
7.8

This CVE describes an out-of-bounds read vulnerability in Rockwell Automation Arena software that could allow arbitrary code execution. Attackers can ...

Dec 5, 2024
CVE-2024-38658
7.8

An out-of-bounds read vulnerability in Fuji Electric V-Server and V-Server Lite SCADA software allows attackers to disclose sensitive information or e...

Nov 28, 2024
CVE-2024-9767
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SID files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-9755
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Tungsten Automation P...

Nov 22, 2024
CVE-2024-9750
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-8847
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...

Nov 22, 2024
CVE-2024-8837
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XPS files in PDF-XChange Editor. The fla...

Nov 22, 2024
CVE-2024-8840
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious JB2 files. The fla...

Nov 22, 2024
CVE-2024-8833
7.8

CVE-2024-8833 is a remote code execution vulnerability in PDF-XChange Editor's XPS file parser. Attackers can execute arbitrary code by tricking users...

Nov 22, 2024
CVE-2024-8825
7.8

CVE-2024-8825 is an out-of-bounds read vulnerability in PDF-XChange Editor's PDF file parsing that can lead to remote code execution. Attackers can ex...

Nov 22, 2024
CVE-2024-11581
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious JT files...

Nov 22, 2024
CVE-2024-11571
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...

Nov 22, 2024
CVE-2024-11561
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...

Nov 22, 2024
CVE-2024-11563
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11565
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious CGM files. The flaw exists ...

Nov 22, 2024
CVE-2024-11567
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...

Nov 22, 2024
CVE-2024-11569
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...

Nov 22, 2024
CVE-2024-11535
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11537
7.8

This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...

Nov 22, 2024
CVE-2024-11529
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11531
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CGM files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-5510
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Kofax Power PDF. The flaw e...

Nov 22, 2024
CVE-2024-52567
7.8

This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...

Nov 18, 2024
CVE-2024-47940
7.8

This vulnerability in Solid Edge SE2024 allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PSM file...

Nov 12, 2024
CVE-2024-46956
7.8

This vulnerability in Ghostscript allows out-of-bounds memory access in the filenameforall function, which could lead to arbitrary code execution. It ...

Nov 10, 2024
CVE-2024-50158
7.8

This CVE-2024-50158 is an out-of-bounds write vulnerability in the Linux kernel's bnxt_re RDMA driver that could allow local attackers to cause kernel...

Nov 7, 2024
CVE-2024-9827
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk AutoCAD when processing malicious CATPART files. Attackers can cause ...

Oct 29, 2024
CVE-2024-8588
7.8

This vulnerability allows attackers to exploit an out-of-bounds read in AutoCAD's SLDPRT file parser. When a malicious SLDPRT file is opened, attacker...

Oct 29, 2024
CVE-2024-0119
7.8

An unprivileged user can exploit an out-of-bounds read vulnerability in NVIDIA GPU Display Driver for Windows to potentially execute arbitrary code, e...

Oct 26, 2024
CVE-2024-0121
7.8

This vulnerability in NVIDIA GPU Display Driver for Windows allows an unprivileged user to trigger an out-of-bounds read in the user mode layer. Succe...

Oct 26, 2024
CVE-2024-0117
7.8

An out-of-bounds read vulnerability in NVIDIA GPU Display Driver for Windows allows unprivileged users to potentially execute arbitrary code, escalate...

Oct 26, 2024
CVE-2023-32190
7.8

This vulnerability in mlocate's %post script allows the RUN_UPDATEDB_AS user to make arbitrary files world-readable by exploiting insecure file operat...

Oct 16, 2024
CVE-2024-47965
7.8

Delta Electronics CNCSoft-G2 has a buffer over-read vulnerability (CWE-125) that allows attackers to read memory beyond allocated buffers. This can le...

Oct 10, 2024
CVE-2024-47421
7.8

Adobe Framemaker has an out-of-bounds read vulnerability when parsing malicious files, which could allow attackers to execute arbitrary code as the cu...

Oct 9, 2024
CVE-2024-45464
7.8

This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...

Oct 8, 2024
CVE-2024-45466
7.8

This vulnerability allows remote code execution via specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation so...

Oct 8, 2024
CVE-2024-47136
7.8

An out-of-bounds read vulnerability in Kostac PLC Programming Software allows attackers to cause denial-of-service, execute arbitrary code, or disclos...

Oct 3, 2024
CVE-2024-39393
7.8

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file....

Aug 14, 2024

About Out-of-bounds Read (CWE-125)

The product reads data past the end, or before the beginning, of the intended buffer.

Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.

External reference: View CWE-125 on MITRE CWE →

Monitor Out-of-bounds Read Vulnerabilities

Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.

Start Monitoring Free