CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,864 vulnerabilities with CWE-125
CVE-2023-20813 MEDIUM
Android - Out-of-bounds Read in WLAN Service
CVSS 4.4
CVE-2023-20798 MEDIUM
Android - Out-of-bounds Read in PDA Component
CVSS 4.4
CVE-2023-4135 MEDIUM
QEMU 8.0.0-8.0.x - Heap Out-of-bounds Read in Virtual NVMe Device
CVSS 6.0
CVE-2023-25600 HIGH
InsydeH2O < 01.01.04.0016 - Denial of Service via EFI Variable Tampering
CVSS 7.1
CVE-2023-38746 HIGH
CX-One <V9.80 - Info Disclosure/Arbitrary Code Execution
CVSS 7.8
CVE-2023-4072 HIGH
Google Chrome <115.0.5790.170 - Heap Corruption
CVSS 8.8
CVE-2023-33383 MEDIUM
Shelly 4PM Pro <0.11.0 - Memory Corruption
CVSS 5.3
CVE-2023-38559 MEDIUM
Ghostscript < 10.02.0 - Denial of Service via Crafted PDF File for DEVN Device
CVSS 5.5
CVE-2023-4048 HIGH
Firefox < 116 - Out-of-bounds Read via DOMParser HTML Parsing
CVSS 7.5
CVE-2023-34359 HIGH
ASUS RT-AX88U Firmware < 3.0.0.4.388.23748 - Unauthenticated Denial of Service via Crafted JSON Request
CVSS 7.5
CVE-2023-34358 HIGH
ASUS RT-AX88U Firmware < 3.0.0.4.388.23748 - Unauthenticated Denial of Service via Crafted User Agent
CVSS 7.5
CVE-2023-37285 CRITICAL
iPadOS < 15.7.8 - Out-of-bounds Read
CVSS 9.8
CVE-2023-32443 HIGH
macOS 11.0-11.7.9 - Out-of-bounds Read and Denial of Service via File Processing
CVSS 8.1
CVE-2023-3773 MEDIUM
Linux Kernel - Out-of-bounds Read in XFRM Netlink Attribute Parsing
CVSS 5.5
CVE-2023-3745 MEDIUM
ImageMagick 6.0-6.9-11-0 - Denial of Service via Heap-Based Buffer Overflow in PushCharPixel
CVSS 5.5
CVE-2023-2860 MEDIUM
Linux Kernel < 5.19.19 - Out-of-bounds Read in SR-IPv6 Seg6 Attribute Processing
CVSS 4.4
CVE-2023-38432 CRITICAL
Linux kernel <6.3.10 - Memory Corruption
CVSS 9.1
CVE-2023-38431 CRITICAL
Linux kernel <6.3.8 - Info Disclosure
CVSS 9.1
CVE-2023-38430 CRITICAL
Linux kernel <6.3.9 - Memory Corruption
CVSS 9.1
CVE-2023-38428 CRITICAL
Linux kernel <6.3.4 - Info Disclosure
CVSS 9.1
CVE-2023-38427 CRITICAL
Linux kernel <6.3.8 - Info Disclosure
CVSS 9.8
CVE-2023-38426 CRITICAL
Linux kernel <6.3.4 - Buffer Overflow
CVSS 9.1
CVE-2023-38253 MEDIUM
w3m - Denial of Service
CVSS 4.7
CVE-2023-38252 MEDIUM
w3m - Denial of Service
CVSS 4.7
CVE-2023-36838 MEDIUM
Juniper Junos OS on SRX Series Authenticated DoS via CLI Command
CVSS 5.5
Details
Vulnerabilities 8,864