Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 70/185
5.1
CVE-2023-33078

Information Disclosure while processing IOCTL request in FastRPC.

5.1
CVE-2024-27223

In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a m

5.1
CVE-2024-27230

In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a

5.0
CVE-2024-33767

lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source.

5.0
CVE-2024-9843

A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia

5.0
CVE-2024-47250

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou

4.9
CVE-2024-0116

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing

4.9
CVE-2024-20102

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote infor

4.9
CVE-2024-45829

Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly

4.8
CVE-2024-38481

Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attac

4.8
CVE-2023-31339

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged

4.7
CVE-2023-38678

OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

4.7
CVE-2024-20691

Windows Themes Information Disclosure Vulnerability

4.7
CVE-2022-23089

When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1

4.7
CVE-2024-5629

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided

4.7
CVE-2024-30069

Windows Remote Access Connection Manager Information Disclosure Vulnerability

4.7
CVE-2024-29778

In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds rea

4.7
CVE-2024-32898

In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a miss

4.7
CVE-2024-32904

In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bo

4.7
CVE-2024-7347

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-

4.6
CVE-2024-20882

Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary d

4.6
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora

4.4
CVE-2023-32875

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform

4.4
CVE-2023-32876

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform

4.4
CVE-2023-32878

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati

4.4
CVE-2023-32880

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati

4.4
CVE-2024-20820

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Ou

4.4
CVE-2023-49100

Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed

4.4
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such

4.4
CVE-2024-27319

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONN

4.4
CVE-2024-27225

In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could

4.4
CVE-2024-21920

A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyon

4.4
CVE-2024-20041

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo

4.4
CVE-2024-29755

In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to loca

4.4
CVE-2023-52536

In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial

4.4
CVE-2024-20058

In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.4
CVE-2024-20071

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform

4.4
CVE-2024-38123

Windows Bluetooth Driver Information Disclosure Vulnerability

4.4
CVE-2024-20084

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis

4.4
CVE-2024-20085

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis

4.4
CVE-2024-20088

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.4
CVE-2024-27364

An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos

4.4
CVE-2024-27366

An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn

4.4
CVE-2024-27367

An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exyno

4.4
CVE-2024-27368

An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850,

4.4
CVE-2024-6876

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited interna

4.4
CVE-2024-20091

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc

4.4
CVE-2024-20093

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc

4.4
CVE-2024-20095

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2024-20096

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started