CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,160 vulnerabilities with CWE-125
CVE-2026-43703 MEDIUM
Apple Ios And iPadOS - Out-of-bounds Read
CVSS 6.5
CVE-2026-43676 MEDIUM
Apple Safari - Out-of-bounds Read
CVSS 6.5
CVE-2026-28979 MEDIUM
Apple Safari - Out-of-bounds Read
CVSS 6.5
CVE-2026-9267 MEDIUM
Eclipse Tinydtls - Out-of-bounds Read
CVE-2026-13522 MEDIUM
Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds
CVSS 4.3
CVE-2026-45258 HIGH
FreeBSD sound(4) mmap - Integer Overflow Privilege Escalation
CVSS 7.8
CVE-2026-48770 MEDIUM
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
CVSS 5.0
CVE-2026-53303 HIGH
f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
CVSS 7.1
CVE-2026-54341 HIGH
Dragonfly: RESTORE operations may crash the server
CVSS 7.5
CVE-2026-5757 HIGH
Ollama Model Quantization Engine - Unauthenticated Heap Memory Disclosure
CVSS 7.5
CVE-2026-12340 HIGH
Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
CVSS 7.5
CVE-2026-56788 MEDIUM
RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri
CVSS 4.4
CVE-2026-12897 HIGH
Out-of-bounds read in Horner Automation Cscape
CVE-2026-6094 CRITICAL
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
CVSS 9.1
CVE-2026-57454 MEDIUM
Vim: Out-of-bounds Read with Text Properties
CVSS 6.1
CVE-2026-57452 MEDIUM
Vim: Out-of-bounds Read with libsodium-encrypted Files
CVSS 5.5
CVE-2026-57451 MEDIUM
Vim: Out-of-bounds Read in Text Property Count
CVSS 5.3
CVE-2026-57235 HIGH
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVSS 8.2
CVE-2026-4526 MEDIUM
Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-47154 MEDIUM
Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-47149 MEDIUM
Door Lock GetUserType invalid table index in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-47148 MEDIUM
Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-47147 HIGH
OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2
CVSS 7.1
CVE-2026-53268 HIGH
netfilter: conntrack_irc: fix possible out-of-bounds read
CVSS 8.2
CVE-2026-53255 HIGH
Bluetooth: MGMT: validate advertising TLV before type checks
CVSS 7.1
Details
Vulnerabilities 9,160