CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,471 vulnerabilities with CWE-125
CVE-2026-28532 MEDIUM
FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions
CVSS 6.5
CVE-2026-42799 HIGH
ASR Kestrel < 2026/02/10 - Out-of-Bounds Access
CVSS 7.4
CVE-2026-40686 LOW
Exim < 4.99.2 - Out-of-Bounds Access
CVSS 3.7
CVE-2026-7425 MEDIUM
Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP
CVSS 6.5
CVE-2026-2810 MEDIUM
Endpoint DLP Driver Out-of-Bounds Read
CVE-2026-7354 HIGH
Google Chrome < 147.0.7727.138 - Out-of-Bounds Access
CVSS 8.8
CVE-2026-41607 MEDIUM
Apache Thrift: C++ JSON OOB read
CVSS 6.5
CVE-2026-41604 HIGH
Apache Thrift: Swift Range crash in skip()
CVSS 8.2
CVE-2026-7233 LOW
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
CVSS 3.3
CVE-2026-7135 MEDIUM
GPAC MP4Box box_code_base.c elng_box_read out-of-bounds
CVSS 5.3
CVE-2026-6786 HIGH
Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 8.1
CVE-2026-6785 HIGH
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 8.1
CVE-2026-41503 HIGH
BACnet Stack: Out-of-Bounds Read in ReadPropertyMultiple Property Decoder via Deprecated Tag Parser
CVSS 7.5
CVE-2026-41502 HIGH
BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder
CVSS 7.5
CVE-2026-41475 CRITICAL
BACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated Tag Parser
CVSS 9.1
CVE-2026-41415 CRITICAL
PJSIP: SIP Multipart CID URI Length Underflow
CVSS 9.1
CVE-2026-41677 CRITICAL
rust-openssl 0.9.0-0.10.77 - Memory Corruption
CVSS 9.1
CVE-2026-41079 MEDIUM
OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
CVSS 4.3
CVE-2026-31641 HIGH
rxrpc: Fix RxGK token loading to check bounds
CVSS 7.8
CVE-2026-31636 CRITICAL
rxrpc: fix RESPONSE authenticator parser OOB read
CVSS 9.1
CVE-2026-31614 HIGH
smb: client: fix off-by-8 bounds check in check_wsl_eas()
CVSS 7.1
CVE-2026-31613 HIGH
smb: client: fix OOB reads parsing symlink error response
CVSS 8.1
CVE-2026-31570 HIGH
Linux - Out-of-Bounds Access
CVSS 8.8
CVE-2026-31569 HIGH
LoongArch: KVM: Handle the case that EIOINTC's coremap is empty
CVSS 7.3
CVE-2026-31568 HIGH
s390/mm: Add missing secure storage access fixups for donated memory
CVSS 7.1
Details
Vulnerabilities 8,471