CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,778 vulnerabilities with CWE-125
CVE-2026-6785 HIGH
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 7.5
CVE-2026-31675 HIGH
net/sched: sch_netem: fix out-of-bounds access in packet corruption
CVSS 7.8
CVE-2026-41503 HIGH
BACnet Stack: Out-of-Bounds Read in ReadPropertyMultiple Property Decoder via Deprecated Tag Parser
CVSS 7.5
CVE-2026-41502 HIGH
BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder
CVSS 7.5
CVE-2026-41475 CRITICAL
BACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated Tag Parser
CVSS 9.1
CVE-2026-41415 CRITICAL
PJSIP: SIP Multipart CID URI Length Underflow
CVSS 9.1
CVE-2026-41677 CRITICAL
rust-openssl 0.9.0-0.10.77 - Memory Corruption
CVSS 9.1
CVE-2026-41079 MEDIUM
OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
CVSS 4.3
CVE-2026-31641 HIGH
rxrpc: Fix RxGK token loading to check bounds
CVSS 7.8
CVE-2026-31636 CRITICAL
rxrpc: fix RESPONSE authenticator parser OOB read
CVSS 9.1
CVE-2026-31614 HIGH
Linux Kernel SMB Client - Out-of-Bounds Read
CVSS 7.1
CVE-2026-31613 HIGH
smb: client: fix OOB reads parsing symlink error response
CVSS 8.1
CVE-2026-31570 HIGH
Linux - Out-of-bounds Read in cgw_csum_crc8_rel()
CVSS 8.8
CVE-2026-31569 HIGH
LoongArch: KVM: Handle the case that EIOINTC's coremap is empty
CVSS 7.3
CVE-2026-31568 HIGH
s390/mm: Add missing secure storage access fixups for donated memory
CVSS 7.1
CVE-2026-31558 HIGH
LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
CVSS 8.8
CVE-2026-33317 HIGH
OP-TEE 3.13.0-4.10.0 - Out-of-bounds Read in PKCS#11 TA Heap via Bad Template Parameter
CVSS 8.7
CVE-2026-28525 MEDIUM
SWUpdate Integer Underflow in Multipart Upload Parser
CVSS 6.8
CVE-2026-6920 CRITICAL
Google Chrome < 147.0.7727.117 - Out-of-bounds Read in GPU
CVSS 9.6
CVE-2026-34003 HIGH
Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
CVSS 7.8
CVE-2026-33599 LOW
PowerDNS dnsdist Service Discovery - Out-of-Bounds Read
CVSS 3.1
CVE-2026-33598 MEDIUM
Out-of-bounds read in cache inspection via Lua
CVSS 4.8
CVE-2026-31528 HIGH
perf: Make sure to use pmu_ctx->pmu for groups
CVSS 7.8
CVE-2026-31513 HIGH
Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req
CVSS 8.1
CVE-2026-31484 HIGH
io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check
CVSS 7.1
Details
Vulnerabilities 8,778