Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 60/185
7.1
CVE-2024-56650

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: fix LED ID check in led_tg_che

7.1
CVE-2024-56721

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode a

7.0
CVE-2024-26660

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream

6.8
CVE-2023-51456

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 c

6.8
CVE-2023-43527

Information disclosure while parsing dts header atom in Video.

6.8
CVE-2024-37086

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a v

6.8
CVE-2024-6505

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the ind

6.8
CVE-2024-43449

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-43634

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-43637

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-43638

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-43643

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-49077

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-49078

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-49083

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-49092

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.8
CVE-2024-49110

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.7
CVE-2024-20022

In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of

6.7
CVE-2024-29783

In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local

6.7
CVE-2023-25494

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could a

6.7
CVE-2023-49144

Out of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow

6.7
CVE-2018-9390

In procfile_write of gl_proc.c, there is a possible out of bounds read of a function pointer due to an incorrect bo

6.6
CVE-2024-27282

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it

6.6
CVE-2024-49101

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

6.6
CVE-2024-49109

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

6.6
CVE-2024-49111

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

6.5
CVE-2024-20660

Microsoft Message Queuing Information Disclosure Vulnerability

6.5
CVE-2024-21314

Microsoft Message Queuing Information Disclosure Vulnerability

6.5
CVE-2023-47993

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-o

6.5
CVE-2023-42862

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4

6.5
CVE-2023-42865

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4

6.5
CVE-2023-45229

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option

6.5
CVE-2023-45231

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redire

6.5
CVE-2023-41252

Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authent

6.5
CVE-2024-0045

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could l

6.5
CVE-2024-2626

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bo

6.5
CVE-2024-27094

OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes

6.5
CVE-2024-26226

Windows Distributed File System (DFS) Information Disclosure Vulnerability

6.5
CVE-2024-21618

An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Junipe

6.5
CVE-2024-3855

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability

6.5
CVE-2024-3839

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sens

6.5
CVE-2024-23533

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi

6.5
CVE-2024-25569

An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DIC

6.5
CVE-2024-4059

Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data v

6.5
CVE-2023-46280

A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All ve

6.5
CVE-2023-43537

Information disclosure while handling T2LM Action Frame in WLAN Host.

6.5
CVE-2024-5268

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows n

6.5
CVE-2024-3017

In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (

6.5
CVE-2024-21456

Information Disclosure while parsing beacon frame in STA.

6.5
CVE-2024-21457

INformation disclosure while handling Multi-link IE in beacon frame.

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started