CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Read CVEs (1,715)
This vulnerability allows attackers to gain elevated SYSTEM privileges on Windows systems by exploiting a memory corruption flaw in the Kernel Streami...
Aug 13, 2024This vulnerability in NX software allows attackers to execute arbitrary code or crash the application by exploiting an out-of-bounds read when parsing...
Aug 13, 2024This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read vulnerability in PDF parsing functionality. It affec...
Aug 12, 2024This vulnerability in NVIDIA GPU Display Driver for Windows allows an unprivileged user to trigger an out-of-bounds read in the user mode layer. Succe...
Aug 8, 2024An out-of-bounds read vulnerability in LabVIEW allows attackers to read memory beyond allocated buffers, potentially disclosing sensitive information ...
Jul 23, 2024This vulnerability in the Linux kernel's ax88179_178a USB Ethernet driver allows out-of-bounds memory accesses when processing network packets from ma...
Jul 16, 2024This vulnerability in the Kernel Streaming WOW Thunk Service Driver allows attackers to gain elevated SYSTEM privileges on Windows systems. It affects...
Jul 9, 2024This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious BMP files. All Simcenter Fem...
Jul 9, 2024This CVE describes an out-of-bounds read vulnerability in Acrobat for Edge that could allow an attacker to execute arbitrary code in the context of th...
Jul 2, 2024This vulnerability allows an attacker to execute arbitrary code or cause a denial-of-service by tricking a user into opening a malicious 3DM file in a...
Jun 25, 2024This vulnerability allows attackers to exploit a buffer overflow in Autodesk's opennurbs.dll library when processing malicious 3DM files. Successful e...
Jun 25, 2024This vulnerability allows attackers to exploit out-of-bounds read conditions in Autodesk applications when processing malicious 3DM and MODEL files. A...
Jun 25, 2024A buffer overflow vulnerability in the Linux kernel's TPM SPI driver allows out-of-bounds memory access when processing SPI transfers. This affects sy...
Jun 21, 2024This CVE describes an out-of-bounds array access vulnerability in the Linux kernel's DMA mapping benchmark module. When NUMA_NO_NODE is passed to cpum...
Jun 21, 2024Adobe Photoshop Desktop versions 24.7.3, 25.7 and earlier contain an out-of-bounds read vulnerability when parsing malicious files. An attacker could ...
Jun 13, 2024A use-after-free vulnerability in the Linux kernel's framebuffer (fbdev) subsystem with deferred I/O support allows memory corruption when a framebuff...
May 21, 2024This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM-level privileges through a loca...
May 14, 2024This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious PAR files. All ...
May 14, 2024An out-of-bounds read vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files. This ...
May 14, 2024This vulnerability allows remote code execution through specially crafted X_T files in Siemens JT2Go and Teamcenter Visualization software. An attacke...
May 14, 2024This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious IGS files....
May 14, 2024This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing malicious IGS files....
May 14, 2024This vulnerability in Simcenter Femap allows remote code execution when processing malicious IGS files. An attacker can exploit an out-of-bounds read ...
May 14, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...
May 7, 2024This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files. The flaw e...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. Th...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious JPG files. The fla...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious AR files in Ashlar-Vellum Cobalt. The fl...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious JPG files. The fla...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containi...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files or visit...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files or visit...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening a malicious TIF file in PDF-XChange Editor. The fl...
May 3, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...
May 3, 2024This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files. The flaw e...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files or visiting malicious web page...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious AR files in Ashlar-Vellum Cobalt. Attack...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious IGS files in Ashlar-Vellum Cobalt softwa...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VC...
May 3, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...
May 3, 2024An out-of-bounds read vulnerability in CX-Programmer (part of CX-One) allows attackers to craft malicious project files that, when opened, can crash t...
May 1, 2024This vulnerability is an out-of-bounds memory access flaw in the Linux kernel's NVIDIA DRM driver (nv04). It allows attackers to potentially crash the...
May 1, 2024Adobe Animate versions 23.0.4, 24.0.1 and earlier contain an out-of-bounds read vulnerability when processing malicious files. This could allow an att...
Apr 11, 2024CVE-2024-26175 is a Secure Boot security feature bypass vulnerability that allows attackers to circumvent Secure Boot protections on affected systems....
Apr 9, 2024This vulnerability allows remote code execution through specially crafted X_T files in Siemens JT2Go, Parasolid, and Teamcenter Visualization software...
Apr 9, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...
Apr 3, 2024This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files. The flaw e...
Apr 3, 2024About Out-of-bounds Read (CWE-125)
The product reads data past the end, or before the beginning, of the intended buffer.
Our database tracks 1,715 CVEs classified as CWE-125, with 150 rated critical and 1,017 rated high severity. The average CVSS score for Out-of-bounds Read vulnerabilities is 7.1.
External reference: View CWE-125 on MITRE CWE →
Monitor Out-of-bounds Read Vulnerabilities
Get alerted when new Out-of-bounds Read CVEs affect your infrastructure.
Start Monitoring Free