In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local
In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service
In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d
In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d
In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d
In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information d
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with
In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check
Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visual
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in
Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms
Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms
In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missi
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a
libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to
Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial
A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive
Tungsten Automation Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerab
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect av
Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause feat
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio
An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This fla
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers acce
Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read
Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthori
Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access
Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to
Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x
A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o
A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releas
Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authentica
Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to t
Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A lo
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A lo
There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulner
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started