Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause p
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause p
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause p
Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of ser
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Transient DOS in WLAN Firmware while processing a FTMR frame.
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds rea
In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to r
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandl
mupnp/net/uri.c in mUPnP for C through 3.0.2 has an out-of-bounds read and application crash because it lacks a certain
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value fro
Contiki-NG is an operating system for internet of things devices. In version 4.8 and prior, when processing ICMP DAO pac
there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with S
Microsoft Office Visio Information Disclosure Vulnerability
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malic
In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.
In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to loca
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cf
This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR
NVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of
An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness duri
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verify
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c i
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with i
An authorization issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macO
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, wat
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, lead
Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samb
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This i
In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ
Information disclosure due to buffer overread in Core
Information disclosure due to buffer overread in Core
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command r
Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification r
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-se
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-se
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tool
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-se
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started