Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an
Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system.
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.1
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exc
In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to dr
Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerabilit
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Fix memory allocation size for
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate buffer length while parsing inde
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption during management frame processing due to mismatch in T2LM info element.
A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of s
A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.
The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not chec
In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sy
Memory corruption while decoding of OTA messages from T3448 IE.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Ma
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: dccp: copy entire header to s
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Onl
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during mul
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when subm
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_s
In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_ge
In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR
Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows lo
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lea
In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix the out of bound issue of vmemmap ad
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write sysca
Microsoft Excel Information Disclosure Vulnerability
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit
Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive informati
In the Linux kernel, the following vulnerability has been resolved: net: dsa: Avoid cross-chip syncing of VLAN filterin
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: add missing boundary check in vm_acce
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started