LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service
Information disclosure due to buffer overread in Linux sensors
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos
Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability
In meta wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a lo
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a lo
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with ele
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could all
In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could l
In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could
In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation
In Do_AIMS_SET_CALL_WAITING of imsservice.cpp, there is a possible out of bounds read due to a missing bounds check. Thi
In startWpsPbcInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This c
In initiateTdlsSetupInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. Thi
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt
In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds check. This could l
In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due to a heap buffer over
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated
A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated pri
A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated pri
A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with el
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated pr
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalatio
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalatio
Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.
ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for
The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentia
Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive info
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out
An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an xwrite out-of-bounds read.
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a bz3_decode_block out-of-bounds read.
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential d
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sono
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x
An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message t
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-
Prior to version v1.20230419.0, the FormData API implementation was subject to an integer overflow. If a FormData instan
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started