Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-125

MITRE ↗

Out-of-bounds Read

717
CRITICAL
3,828
HIGH
4,120
MEDIUM
505
LOW
9,243 CVEs · Page 95/185
8.2
CVE-2021-35088

Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago

8.2
CVE-2021-35117

An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna

8.2
CVE-2021-35083

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon

8.2
CVE-2022-34889

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (

8.2
CVE-2022-33319

Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics

8.2
CVE-2022-22062

An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap

8.2
CVE-2022-25706

Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdr

8.2
CVE-2022-25719

Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto

8.2
CVE-2021-34567

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co

8.2
CVE-2022-33235

Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapd

8.2
CVE-2022-33268

Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto,

8.1
CVE-2022-21726

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the

8.1
CVE-2022-21728

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` doe

8.1
CVE-2022-21730

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider

8.1
CVE-2022-23592

Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read

8.1
CVE-2022-0114

Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perf

8.1
CVE-2021-42387

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp

8.1
CVE-2021-42388

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp

8.1
CVE-2022-27607

Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

8.1
CVE-2018-25033

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenera

8.1
CVE-2022-1907

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

8.1
CVE-2022-1908

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

8.1
CVE-2022-1987

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

8.1
CVE-2022-34299

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

8.1
CVE-2021-33644

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo

8.1
CVE-2022-32745

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify t

8.1
CVE-2022-44311

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo)

8.1
CVE-2022-41981

A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-c

8.1
CVE-2022-47940

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length v

8.1
CVE-2022-47943

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and

7.8
CVE-2022-0128

vim is vulnerable to Out-of-bounds Read

7.8
CVE-2021-45055

Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file,

7.8
CVE-2021-34858

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User inter

7.8
CVE-2021-34880

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34885

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34912

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34913

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34927

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34930

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34942

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34946

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-45060

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe

7.8
CVE-2021-40158

A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond

7.8
CVE-2021-40167

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption

7.8
CVE-2022-0368

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

7.8
CVE-2021-4034 KEV

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool

7.8
CVE-2021-44018

A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S

7.8
CVE-2021-46562

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C

7.8
CVE-2021-46563

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C

7.8
CVE-2021-46590

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C

Frequently Asked Questions

What is CWE-125?

CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-125?

There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.

How can I protect against CWE-125 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.

Detect CWE-125 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.

Get Started