The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obta
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If cli
In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There
In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnno
HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_ex
In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs
robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-inser
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enable
Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer ma
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling
FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been detected in the functi
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identifi
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavp
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identifi
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially expl
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of
The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This v
Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially per
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrar
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQo
In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix array index out of bound exception
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix stack-out-of-bounds memory access fro
Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bou
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinc
Windows Kernel Elevation of Privilege Vulnerability
Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially ex
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a
In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The
In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The
Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects
In the Linux kernel, the following vulnerability has been resolved: tty: serial: qcom-geni-serial: fix slab-out-of-boun
Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromise
The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software runni
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: remove unused C2H event ID RTW89_MAC_C
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence
In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing b
Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger o
Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started