Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 74/185
8.8
CVE-2023-46603

In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function

8.6
CVE-2023-3036

An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cf

8.6
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 throu

8.6
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulner

8.4
CVE-2023-42536

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause ou

8.4
CVE-2023-42537

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause

8.2
CVE-2022-33252

Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.

8.2
CVE-2022-33255

Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cm

8.2
CVE-2022-33283

Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.

8.2
CVE-2022-33284

Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.

8.2
CVE-2022-25728

Information disclosure in modem due to buffer over-read while processing response from DNS server

8.2
CVE-2022-25732

Information disclosure in modem due to buffer over read in dns client due to missing length check

8.2
CVE-2022-25738

Information disclosure in modem due to buffer over-red while performing checksum of packet received

8.2
CVE-2022-33229

Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.

8.2
CVE-2022-33271

Information disclosure due to buffer over-read in WLAN while parsing NMF frame.

8.2
CVE-2022-25726

Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet

8.2
CVE-2022-25730

Information disclosure in modem due to improper check of IP type while processing DNS server query

8.2
CVE-2022-25747

Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message

8.2
CVE-2022-33222

Information disclosure due to buffer over-read while parsing DNS response packets in Modem.

8.2
CVE-2022-33228

Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination opti

8.2
CVE-2022-33258

Information disclosure due to buffer over-read in modem while reading configuration parameters.

8.2
CVE-2022-33287

Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.

8.2
CVE-2022-33291

Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.

8.2
CVE-2022-33295

Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its

8.2
CVE-2022-40503

Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.

8.2
CVE-2022-40505

Information disclosure due to buffer over-read in Modem while parsing DNS hostname.

8.2
CVE-2021-26365

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to

8.2
CVE-2023-21669

Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.

8.2
CVE-2023-21625

Information disclosure in Network Services due to buffer over-read while the device receives DNS response.

8.1
CVE-2023-33536

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo

8.1
CVE-2023-33537

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo

8.1
CVE-2023-32443

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.8, macOS

8.1
CVE-2023-4427

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out o

8.1
CVE-2023-4428

Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out

8.1
CVE-2023-4431

Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an ou

8.1
CVE-2023-28543

A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted

8.1
CVE-2023-4761

Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromi

8.1
CVE-2023-48025

Liblisp through commit 4c65969 was discovered to contain a out-of-bounds-read vulnerability in unsigned get_length(lisp_

7.8
CVE-2022-41645

Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and

7.8
CVE-2022-46360

Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker

7.8
CVE-2023-0049

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

7.8
CVE-2022-41613

Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when

7.8
CVE-2023-21772

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2022-41150

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-41152

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-42372

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-42379

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-42399

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-42402

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-42417

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started