CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,715)
This CVE describes an out-of-bounds read vulnerability in the Linux kernel's Operating Performance Point (OPP) framework. An attacker could potentiall...
Feb 27, 2025A missing bounds check in the Linux kernel's i915 graphics driver vm_access() function allows out-of-bounds memory access. This vulnerability could le...
Feb 26, 2025An out-of-bounds read vulnerability in CX-Programmer allows attackers to read sensitive memory contents or cause application crashes. This affects use...
Feb 17, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Tungsten Automation Power P...
Feb 11, 2025This vulnerability in Tungsten Automation Power PDF allows attackers to disclose sensitive information by tricking users into opening malicious JP2 fi...
Feb 11, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Tungsten Automation Power P...
Feb 11, 2025This vulnerability in Microsoft Excel allows an attacker to read sensitive information from memory when a specially crafted file is opened. It affects...
Feb 11, 2025This CVE is a Linux kernel vulnerability in the vfio/platform driver where user-supplied count and offset parameters in read/write syscalls are not pr...
Feb 10, 2025CVE-2018-9464 is a local privilege escalation vulnerability in Android that allows attackers to read protected system files without proper permission ...
Jan 18, 2025This vulnerability allows a local authenticated attacker to perform an out-of-bounds read in Ivanti Endpoint Manager (EPM), potentially leading to pri...
Jan 14, 2025This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...
Dec 30, 2024CVE-2024-12212 is an out-of-bounds read vulnerability in CSP file parsing that could allow arbitrary code execution. This affects users of Horner Auto...
Dec 13, 2024This CVE describes an out-of-bounds read vulnerability in Rockwell Automation Arena software that could allow arbitrary code execution. Attackers can ...
Dec 5, 2024An out-of-bounds read vulnerability in Fuji Electric V-Server and V-Server Lite SCADA software allows attackers to disclose sensitive information or e...
Nov 28, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SID files in IrfanView. The flaw exists ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Tungsten Automation P...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files in Tungsten Automation Power P...
Nov 22, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XPS files in PDF-XChange Editor. The fla...
Nov 22, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious JB2 files. The fla...
Nov 22, 2024CVE-2024-8833 is a remote code execution vulnerability in PDF-XChange Editor's XPS file parser. Attackers can execute arbitrary code by tricking users...
Nov 22, 2024CVE-2024-8825 is an out-of-bounds read vulnerability in PDF-XChange Editor's PDF file parsing that can lead to remote code execution. Attackers can ex...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious JT files...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious CGM files. The flaw exists ...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...
Nov 22, 2024This vulnerability in IrfanView allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files. The flaw exists ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files in IrfanView. The flaw exists ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CGM files in IrfanView. Attackers can ga...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Kofax Power PDF. The flaw e...
Nov 22, 2024This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...
Nov 18, 2024This vulnerability in Solid Edge SE2024 allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PSM file...
Nov 12, 2024This vulnerability in Ghostscript allows out-of-bounds memory access in the filenameforall function, which could lead to arbitrary code execution. It ...
Nov 10, 2024This CVE-2024-50158 is an out-of-bounds write vulnerability in the Linux kernel's bnxt_re RDMA driver that could allow local attackers to cause kernel...
Nov 7, 2024This vulnerability allows attackers to exploit an out-of-bounds read in Autodesk AutoCAD when processing malicious CATPART files. Attackers can cause ...
Oct 29, 2024This vulnerability allows attackers to exploit an out-of-bounds read in AutoCAD's SLDPRT file parser. When a malicious SLDPRT file is opened, attacker...
Oct 29, 2024An unprivileged user can exploit an out-of-bounds read vulnerability in NVIDIA GPU Display Driver for Windows to potentially execute arbitrary code, e...
Oct 26, 2024This vulnerability in NVIDIA GPU Display Driver for Windows allows an unprivileged user to trigger an out-of-bounds read in the user mode layer. Succe...
Oct 26, 2024An out-of-bounds read vulnerability in NVIDIA GPU Display Driver for Windows allows unprivileged users to potentially execute arbitrary code, escalate...
Oct 26, 2024This vulnerability in mlocate's %post script allows the RUN_UPDATEDB_AS user to make arbitrary files world-readable by exploiting insecure file operat...
Oct 16, 2024Delta Electronics CNCSoft-G2 has a buffer over-read vulnerability (CWE-125) that allows attackers to read memory beyond allocated buffers. This can le...
Oct 10, 2024Adobe Framemaker has an out-of-bounds read vulnerability when parsing malicious files, which could allow attackers to execute arbitrary code as the cu...
Oct 9, 2024This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...
Oct 8, 2024This vulnerability allows remote code execution via specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation so...
Oct 8, 2024An out-of-bounds read vulnerability in Kostac PLC Programming Software allows attackers to cause denial-of-service, execute arbitrary code, or disclos...
Oct 3, 2024This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file....
Aug 14, 2024About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free