Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
Information disclosure in modem due to buffer over-read while processing packets from DNS server
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads w
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
Transient DOS in WLAN Firmware while processing frames with missing header fields.
Transient DOS in WLAN Firmware while parsing FT Information Elements.
Transient DOS while parsing WLAN beacon or probe-response frame.
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minu
Windows iSCSI Discovery Service Denial of Service Vulnerability
Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 al
In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lea
In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remo
In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check.
In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. Thi
In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds
In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer
In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds
An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted scri
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds c
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations.
Transient DOS in Audio while remapping channel buffer in media codec decoding.
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Transient DOS in WLAN firmware while parsing MLO (multi-link operation).
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to p
Transient DOS in WLAN Firmware while parsing rsn ies.
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect servic
Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service
In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a
In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds che
A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9
In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.5
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Transient DOS in WLAN Firmware while parsing t2lm buffers.
Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started