CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,160 vulnerabilities with CWE-125
CVE-2026-14384 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-54908 MEDIUM
Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
CVE-2026-53346 HIGH
rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
CVSS 7.1
CVE-2026-53330 HIGH
Linux - Out-of-Bounds Access
CVSS 7.1
CVE-2026-44041 MEDIUM
UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated
CVSS 4.3
CVE-2026-54592 HIGH
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVSS 7.5
CVE-2026-54500 MEDIUM
Oj: intern.c form_attr has an uninitialized stack read
CVSS 5.3
CVE-2026-56361 LOW
ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing
CVSS 3.3
CVE-2026-14090 HIGH
Google Chrome - Out-of-bounds Read
CVSS 8.1
CVE-2026-14063 MEDIUM
Google Chrome - Out-of-Bounds Access
CVSS 5.7
CVE-2026-14011 HIGH
Google Chrome - Out-of-bounds Read
CVSS 8.1
CVE-2026-13975 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 5.3
CVE-2026-13906 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-13890 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 5.3
CVE-2026-13873 MEDIUM
Google Chrome - Out-of-Bounds Access
CVSS 6.5
CVE-2026-13858 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-13820 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-13819 HIGH
Google Chrome - Out-of-bounds Read
CVSS 8.1
CVE-2026-9263 MEDIUM
Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets
CVSS 6.5
CVE-2026-10652 MEDIUM
Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
CVSS 4.8
CVE-2026-8451 HIGH
NetScaler - Insufficient Input Validation Leading to Memory Overread
CVSS 7.5
CVE-2026-58011 MEDIUM
Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
CVSS 6.5
CVE-2026-10817 HIGH
NetScaler - Insufficient Input Validation Leading to Memory Overread
CVSS 7.5
CVE-2026-56017 HIGH
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash
CVSS 7.5
CVE-2026-43712 MEDIUM
Apple Safari - Out-of-bounds Read
CVSS 6.5
Details
Vulnerabilities 9,160