In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function
An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cf
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 throu
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulner
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause ou
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cm
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
Information disclosure in modem due to buffer over-read while processing response from DNS server
Information disclosure in modem due to buffer over read in dns client due to missing length check
Information disclosure in modem due to buffer over-red while performing checksum of packet received
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet
Information disclosure in modem due to improper check of IP type while processing DNS server query
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message
Information disclosure due to buffer over-read while parsing DNS response packets in Modem.
Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination opti
Information disclosure due to buffer over-read in modem while reading configuration parameters.
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.8, macOS
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out o
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an ou
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromi
Liblisp through commit 4c65969 was discovered to contain a out-of-bounds-read vulnerability in unsigned get_length(lisp_
Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and
Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when
Windows Kernel Elevation of Privilege Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started