In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check
In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead t
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary cod
JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix OOB Read in qrtr_endpoint_post Syzb
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize fie
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Ex
Memory corruption when the captureRead QDCM command is invoked from user-space.
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bh
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs fro
wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.
wasm3 139076a contains memory leaks in Read_utf8.
In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial out-of-bounds when buffer offs
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr
Information disclosure in Modem while processing SIB5.
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting I
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vu
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb2_allocate_rsp_
Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing
Information disclosure in Video while parsing mp2 clip with invalid section length.
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerab
All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calcu
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file c
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_u
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: refactor malicious adv data check Check
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When ther
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with fo
Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_r
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cg
Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect a
HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started