In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local informatio
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A malic
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 an
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvO
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BM
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosur
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosur
In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local informa
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially cr
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. Th
In PVInitVideoEncoder of mp4enc_api.cpp, there is a possible out of bounds read due to a heap buffer overflow. This coul
In (TBD) of (TBD), there is a possible out of bounds read due to memory corruption. This could lead to local information
In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local infor
Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
vim is vulnerable to Out-of-bounds Read
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because off
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in vi
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the h
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade
An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data r
An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to conver
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall numb
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send mal
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer l
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension,
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause
There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SP
In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosur
The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those funct
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started