Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 71/185
4.4
CVE-2024-20097

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc

4.4
CVE-2024-47028

In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local

4.4
CVE-2024-20112

In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service

4.4
CVE-2024-20117

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d

4.4
CVE-2024-20122

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d

4.4
CVE-2024-20123

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d

4.4
CVE-2024-20124

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d

4.4
CVE-2024-38654

Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with

4.4
CVE-2024-20116

In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc

4.4
CVE-2018-9408

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check

4.4
CVE-2024-54114

Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability

4.3
CVE-2024-21099

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visual

4.3
CVE-2024-35385

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in

4.3
CVE-2024-24583

Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms

4.3
CVE-2024-24584

Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms

4.3
CVE-2024-32915

In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missi

4.3
CVE-2024-40630

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a

4.3
CVE-2024-6874

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to

4.3
CVE-2024-9143

Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial

4.3
CVE-2023-20094

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive

4.3
CVE-2024-9758

Tungsten Automation Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerab

4.3
CVE-2024-49098

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

4.3
CVE-2024-49099

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

4.3
CVE-2024-49103

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

4.3
CVE-2024-54115

Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect av

4.3
CVE-2024-54116

Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause feat

4.3
CVE-2024-56378

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio

4.0
CVE-2023-39197

An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This fla

4.0
CVE-2024-20814

Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers acce

4.0
CVE-2024-23912

Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read

4.0
CVE-2024-34632

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthori

4.0
CVE-2024-34633

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access

4.0
CVE-2024-34634

Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to

4.0
CVE-2024-34635

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access

4.0
CVE-2024-34658

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

4.0
CVE-2024-20505

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x

4.0
CVE-2023-4458

A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o

4.0
CVE-2023-39180

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releas

3.9
CVE-2023-22656

Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authentica

3.9
CVE-2021-46772

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to t

3.9
CVE-2024-32667

Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service

3.8
CVE-2024-0154

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A lo

3.8
CVE-2024-0173

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A lo

3.8
CVE-2024-29948

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulner

3.7
CVE-2024-24564

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star

3.7
CVE-2020-1818

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP

3.7
CVE-2020-1819

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP

3.7
CVE-2020-1820

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP

3.7
CVE-2020-1821

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP

3.7
CVE-2020-1822

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started