CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,778 vulnerabilities with CWE-125
CVE-2026-43197 CRITICAL
netconsole: avoid OOB reads, msg is not nul-terminated
CVSS 9.1
CVE-2026-43190 HIGH
netfilter: xt_tcpmss: check remaining length before reading optlen
CVSS 8.2
CVE-2026-43141 HIGH
Linux - Out-of-bounds Read in NTB Switchtec MW LUT Handling
CVSS 7.1
CVE-2026-43112 HIGH
fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
CVSS 8.8
CVE-2026-43083 CRITICAL
net: ioam6: fix OOB and missing lock
CVSS 9.1
CVE-2026-30923 HIGH
libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings
CVSS 7.5
CVE-2026-43071 CRITICAL
dcache: Limit the minimal number of bucket to two
CVSS 9.1
CVE-2026-43070 HIGH
bpf: Reset register ID for BPF_END value tracking
CVSS 7.8
CVE-2026-34000 MEDIUM
X.Org X Server Xwayland - XKB Geometry Out-of-Bounds Read
CVSS 6.1
CVE-2026-6918 HIGH
Eclipse OpenJ9 0.21-0.58 - Unauthenticated Denial of Service via Crafted TCP Message
CVSS 7.5
CVE-2026-37461 HIGH
gobgp < 4.4.0 - Denial of Service via Crafted BGP UPDATE Message
CVSS 7.5
CVE-2026-34032 MEDIUM
Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVSS 5.3
CVE-2026-33857 MEDIUM
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVSS 5.3
CVE-2026-7482 CRITICAL
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
CVSS 9.1
CVE-2026-7737 MEDIUM
osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds
CVSS 5.3
CVE-2026-20447 MEDIUM
MediaTek chipset MT6768 - Privilege Escalation
CVSS 6.7
CVE-2026-7668 HIGH
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
CVSS 7.3
CVE-2026-35233 MEDIUM
Oracle Linux 8-10 - Out-of-bounds Read in ELF Parser via sh_link Field
CVSS 4.4
CVE-2026-37535 HIGH
openxc/isotp-c Out-of-bounds Read in ISO-TP Single Frame Receive Handler
CVSS 7.1
CVE-2026-42481 MEDIUM
Open CASCADE Technology V8_0_0_rc5 - Memory Corruption
CVSS 5.5
CVE-2026-42480 MEDIUM
Open CASCADE Technology V8_0_0_rc5 - DoS
CVSS 5.5
CVE-2026-43051 HIGH
HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
CVSS 8.1
CVE-2026-43048 HIGH
HID: core: Mitigate potential OOB by removing bogus memset()
CVSS 8.8
CVE-2026-43042 HIGH
mpls: add seqcount to protect the platform_label{,s} pair
CVSS 7.1
CVE-2026-43025 HIGH
netfilter: ctnetlink: ignore explicit helper on new expectations
CVSS 7.3
Details
Vulnerabilities 8,778