Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 76/185
7.8
CVE-2022-28311

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C

7.8
CVE-2022-28647

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C

7.8
CVE-2022-37349

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-37350

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-37363

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-37366

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-37367

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2022-37388

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.

7.8
CVE-2022-43616

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphi

7.8
CVE-2023-29053

A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The

7.8
CVE-2023-26371

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted fi

7.8
CVE-2023-26425

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds

7.8
CVE-2023-26389

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a

7.8
CVE-2023-26391

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a

7.8
CVE-2023-26393

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a

7.8
CVE-2023-26402

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a

7.8
CVE-2023-26398

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-26409

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-26411

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-27912

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious a

7.8
CVE-2023-27915

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability

7.8
CVE-2023-27906

A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerabilit

7.8
CVE-2023-2176

A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The imp

7.8
CVE-2023-27938

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in GarageBand for macOS 10

7.8
CVE-2023-27946

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4

7.8
CVE-2023-27949

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, macOS Mon

7.8
CVE-2023-29460

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that

7.8
CVE-2023-29461

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that

7.8
CVE-2023-24902

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2023-29273

Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-29274

Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-29275

Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-29280

Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-29281

Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing

7.8
CVE-2023-25008

A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability

7.8
CVE-2023-32545

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CS

7.8
CVE-2023-32281

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP).

7.8
CVE-2023-32289

The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP

7.8
CVE-2023-27916

The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT

7.8
CVE-2023-31278

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This coul

7.8
CVE-2023-33123

A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions <

7.8
CVE-2023-29167

Out-of-bound reads vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sen

7.8
CVE-2023-32017

Microsoft PostScript Printer Driver Remote Code Execution Vulnerability

7.8
CVE-2023-32029

Microsoft Excel Remote Code Execution Vulnerability

7.8
CVE-2023-31239

Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attack

7.8
CVE-2023-32270

Access of memory location after end of buffer issue exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a spec

7.8
CVE-2023-32288

Out-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM f

7.8
CVE-2023-32542

Out-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 fi

7.8
CVE-2023-25003

A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read

7.8
CVE-2023-26085

A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Andr

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started