Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 79/185
7.5
CVE-2023-27730

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.

7.5
CVE-2023-21769

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2023-24931

Windows Secure Channel Denial of Service Vulnerability

7.5
CVE-2022-25731

Information disclosure in modem due to buffer over-read while processing packets from DNS server

7.5
CVE-2021-31239

An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c

7.5
CVE-2021-46749

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management

7.5
CVE-2021-46765

Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads w

7.5
CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management

7.5
CVE-2023-21658

Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.

7.5
CVE-2023-21659

Transient DOS in WLAN Firmware while processing frames with missing header fields.

7.5
CVE-2023-21660

Transient DOS in WLAN Firmware while parsing FT Information Elements.

7.5
CVE-2023-21661

Transient DOS while parsing WLAN beacon or probe-response frame.

7.5
CVE-2023-24535

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minu

7.5
CVE-2023-32011

Windows iSCSI Discovery Service Denial of Service Vulnerability

7.5
CVE-2023-30362

Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 al

7.5
CVE-2023-21180

In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lea

7.5
CVE-2023-21186

In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remo

7.5
CVE-2023-21197

In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check.

7.5
CVE-2023-21201

In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. Thi

7.5
CVE-2023-21223

In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds

7.5
CVE-2023-21224

In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer

7.5
CVE-2023-21226

In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds

7.5
CVE-2023-36201

An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted scri

7.5
CVE-2023-32044

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2023-32045

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2023-35694

In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds c

7.5
CVE-2023-34358

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req

7.5
CVE-2023-34359

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req

7.5
CVE-2023-4048

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations.

7.5
CVE-2023-28555

Transient DOS in Audio while remapping channel buffer in media codec decoding.

7.5
CVE-2023-39396

Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability

7.5
CVE-2023-39908

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations

7.5
CVE-2023-33015

Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

7.5
CVE-2023-33016

Transient DOS in WLAN firmware while parsing MLO (multi-link operation).

7.5
CVE-2023-42821

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to p

7.5
CVE-2023-33027

Transient DOS in WLAN Firmware while parsing rsn ies.

7.5
CVE-2023-44103

Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect servic

7.5
CVE-2023-44114

Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service

7.5
CVE-2023-35652

In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a

7.5
CVE-2023-35661

In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds che

7.5
CVE-2023-23581

A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9

7.5
CVE-2023-35656

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c

7.5
CVE-2023-35663

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul

7.5
CVE-2023-31122

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.5

7.5
CVE-2023-21347

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio

7.5
CVE-2023-21353

In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc

7.5
CVE-2023-33047

Transient DOS in WLAN Firmware while parsing no-inherit IES.

7.5
CVE-2023-33048

Transient DOS in WLAN Firmware while parsing t2lm buffers.

7.5
CVE-2023-33061

Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.

7.5
CVE-2023-5998

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started