In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. Th
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic
<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explic
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A rem
A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a
An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c7
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70
Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and
Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39
In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack compo
An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a vali
An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension head
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_hand
In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check.
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. T
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent
There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with
An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown me
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via out-of
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of
The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free whe
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_re
Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snap
Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be ex
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A loc
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A loc
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A loc
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon
Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in
Slab-out-of-bounds access can occur if the context pointer is invalid due to lack of null check on pointer before access
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities.
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities.
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities.
Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions ea
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_rea
Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in com
Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdrago
Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in
Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto
When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started