FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received,
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attack
Information disclosure in Automotive multimedia due to buffer over-read.
A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note
In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lea
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead
Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potential
Event Tracing for Windows Information Disclosure Vulnerability
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local in
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to c
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker
Denial of service while processing fastboot flash command on mmc due to buffer over read
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5
Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a
An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in r
xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked
Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enab
In btm_read_link_quality_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. T
In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This coul
In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. Thi
In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due to an incorrect bound
In btm_delete_stored_link_key_complete of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key enc
In watchdog, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation o
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker w
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker wi
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may
In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati
In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information di
In ccu, there is a possible out of bounds read due to a logic error. This could lead to local information disclosure wit
An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to
Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged
NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious
In multiple functions of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could
In btm_ble_read_remote_features_complete of btm_ble_gap.cc, there is a possible out of bounds read due to improper input
In btu_ble_rc_param_req_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This c
In btm_read_tx_power_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This
In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This c
In ParseBqrLinkQualityEvt of btif_bqr.cc, there is a possible out of bounds read due to a missing bounds check. This cou
In btm_ble_clear_resolving_list_completecomplete of btm_ble_privacy.cc, there is a possible out of bounds read due to a
In btm_ble_write_adv_enable_complete of btm_ble_gap.cc, there is a possible out of bounds read due to a missing bounds c
In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This c
In btm_ble_process_periodic_adv_sync_lost_evt of ble_scanner_hci_interface.cc , there is a possible out of bounds read d
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started