In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This c
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the
In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds read due to
In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to improper input valid
In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to local info
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In the m4v_h263 codec, there is a possible out of bounds read due to a use after free. This could lead to local informat
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message
An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to pr
In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could
In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSect
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability.
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect
In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could le
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. An appli
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. A malici
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An appli
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An appli
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An appli
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser
An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd par
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indo
An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1.
OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMea
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in nc
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started