An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect c
In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE bef
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too
Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information d
In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote
In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to remote inf
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote informa
In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote informa
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In netd, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosur
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote informa
In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial
RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Editi
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a differ
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started