Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 21/185
5.5
CVE-2026-17572

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows att

5.5
CVE-2026-43738

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequ

5.5
CVE-2026-43817

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO

5.5
CVE-2026-64776

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m

5.5
CVE-2026-17550

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili

5.5
CVE-2026-20494

In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc

5.5
CVE-2026-68742

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen

5.5
CVE-2026-68743

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length

5.5
CVE-2026-7405

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B

5.5
CVE-2026-66151

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the

5.5
CVE-2026-59128

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally

5.5
CVE-2026-61933

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62703

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62738

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62743

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62786

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62796

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62842

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-62887

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-63517

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63521

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63524

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63528

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63529

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63530

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63531

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-64899

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-64917

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-65662

Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.

5.5
CVE-2026-65784

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-66806

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-66809

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-68797

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-68802

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-68808

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-68813

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70310

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70315

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-16883

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out

5.5
CVE-2026-76923

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2026-76924

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2024-58377

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. No

5.5
CVE-2026-13478

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by p

5.5
CVE-2026-59983

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-71441

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An att

5.5
CVE-2026-75752

Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memo

5.5
CVE-2026-59985

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-61555

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-34616

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex

5.4
CVE-2026-23568

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (Noma

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started