Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 41/185
6.3
CVE-2025-46819

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user

6.2
CVE-2025-20944

Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read

6.2
CVE-2025-46591

Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability

6.2
CVE-2025-12829

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an

6.1
CVE-2024-33067

Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received

6.1
CVE-2024-43063

information disclosure while invoking the mailbox read API.

6.1
CVE-2024-38414

Information disclosure while processing information on firmware image during core initialization.

6.1
CVE-2024-38416

Information disclosure during audio playback.

6.1
CVE-2024-38417

Information disclosure while processing IO control commands.

6.1
CVE-2025-20026

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauth

6.1
CVE-2025-49175

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the serve

6.1
CVE-2025-55097

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss

6.1
CVE-2025-55098

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss

6.1
CVE-2025-55099

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss

6.1
CVE-2025-53055

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

6.1
CVE-2025-64505

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)

6.1
CVE-2025-64506

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)

6.1
CVE-2025-14104

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, spe

6.0
CVE-2025-37149

A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.

5.9
CVE-2024-54090

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v

5.9
CVE-2025-4082

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vul

5.9
CVE-2025-49133

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, w

5.9
CVE-2025-23333

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

5.9
CVE-2025-23334

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

5.9
CVE-2025-7698

Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer

5.9
CVE-2025-9232

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p

5.9
CVE-2025-41739

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the C

5.7
CVE-2017-13317

In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input val

5.7
CVE-2017-13318

In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. Thi

5.7
CVE-2024-57958

Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may caus

5.7
CVE-2025-29974

Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an

5.7
CVE-2025-48002

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent

5.7
CVE-2025-23272

NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially

5.6
CVE-2024-33607

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user

5.6
CVE-2025-31937

Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may all

5.5
CVE-2024-53839

In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. Th

5.5
CVE-2024-45559

Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.

5.5
CVE-2024-45070

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

5.5
CVE-2025-21257

Windows WLAN AutoConfig Service Information Disclosure Vulnerability

5.5
CVE-2025-21374

Windows CSC Service Information Disclosure Vulnerability

5.5
CVE-2024-54507

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, mac

5.5
CVE-2025-24092

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3.

5.5
CVE-2025-24149

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPad

5.5
CVE-2025-21124

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could le

5.5
CVE-2025-20648

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

5.5
CVE-2024-43056

Transient DOS during hypervisor virtual I/O operation in a virtual machine.

5.5
CVE-2025-20042

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

5.5
CVE-2025-21098

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass

5.5
CVE-2025-20913

Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to

5.5
CVE-2025-20914

Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attacke

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started