Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an un
Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows r
In the Linux kernel, the following vulnerability has been resolved: phy: ti: Fix missing sentinel for clk_div_table _g
In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read i
In the Linux kernel, the following vulnerability has been resolved: bpf: add check for invalid name in btf_name_valid_s
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are w
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Adjust VSDB parser for replay feat
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64
In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions Acc
In the Linux kernel, the following vulnerability has been resolved: NFS: fs_context: validate UDP retrans to prevent sh
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_frag: fix stack OOB read while fragm
In the Linux kernel, the following vulnerability has been resolved: mtd: physmap: physmap-bt1-rom: Fix unintentional st
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Retrieve all the PDOs instead of
In the Linux kernel, the following vulnerability has been resolved: ataflop: potential out of bounds in do_format() Th
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not attempt to read past "commit"
In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Disable KASAN in apply_alternativ
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: assert requested protocol is valid The p
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: ipc: Disable and reenable ACPI
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_p
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix OOB read If the index provide
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: fix global-out-of-bounds issue
In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in
In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix incorrect structure acc
In the Linux kernel, the following vulnerability has been resolved: s390/ptrace: handle setting of fpc register correct
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix operation precedence bug in port tim
Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows
In the Linux kernel, the following vulnerability has been resolved: btrfs: dev-replace: properly validate device names
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_rea
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_rep
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check the inode number is not the invalid
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix mmhub client id out-of-bounds acces
Foxit PDF Reader XFA Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remot
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read
In the Linux kernel, the following vulnerability has been resolved: netfilter: validate user input for expected length
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix not validating setsockopt us
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user
In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP option
In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-ra
In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_comman
In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc
In the Linux kernel, the following vulnerability has been resolved: hwmon: (mlxreg-fan) Return non-zero value when fan
In the Linux kernel, the following vulnerability has been resolved: thermal: intel: powerclamp: fix mismatch in get fun
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Fix user-memory-access bug in uclogic
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started