A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulne
A vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read dur
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catal
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-00
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. Pr
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-00
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful e
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDro
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetRetur
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-boun
TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d
Out-of-bounds read in gather_tree in PaddlePaddle before 2.4.
An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/w
Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. Th
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds re
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s
An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted
NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, whi
Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Conn
Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT
Information disclosure in video due to buffer over-read while parsing avi files in Snapdragon Auto, Snapdragon Compute,
TensorFlow is an open source platform for machine learning. When ops that have specified input sizes receive a differing
TensorFlow is an open source platform for machine learning. When the `BaseCandidateSamplerOp` function receives a value
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an esc
In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local informati
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This c
There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passe
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to lo
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation
In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This co
In TBD of ufdt_convert, there is a possible out of bounds read due to memory corruption. This could lead to local escala
In StringsRequestData::encode of requestdata.cpp, there is a possible out of bounds read due to improper input validatio
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read se
In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to loca
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vu
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, w
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Den
Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a dire
Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direc
Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that cause
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started