An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Transient DOS while parsing probe response and assoc response frame.
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS E
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword se
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. C
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. T
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Transient DOS while processing the CU information from RNR IE.
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot
Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una
A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack o
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This coul
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This
In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_adv
CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensiti
The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More
Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction pr
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l
Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption dur
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote inform
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discove
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtde
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPa
Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo
Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started