Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdr
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapd
Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto,
Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the
Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` doe
Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider
Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perf
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp
Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenera
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify t
html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo)
A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-c
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length v
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and
vim is vulnerable to Out-of-bounds Read
Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file,
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User inter
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started