Information Disclosure while processing IOCTL request in FastRPC.
In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a m
In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source.
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou
NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote infor
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attac
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged
OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
Windows Themes Information Disclosure Vulnerability
When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided
Windows Remote Access Connection Manager Information Disclosure Vulnerability
In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds rea
In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a miss
In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bo
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary d
Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Ou
Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed
c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONN
In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could
A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyon
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to loca
In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform
Windows Bluetooth Driver Information Disclosure Vulnerability
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio
An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos
An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn
An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exyno
An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850,
Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited interna
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started