CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
8,784 vulnerabilities with CWE-125
CVE-2026-40253
MEDIUM
openCryptoki: Memory safety vulnerabilities in BER/DER decoders in asn1.c
CVSS 6.8
CVE-2026-41034
MEDIUM
ONLYOFFICE DocumentServer < 9.3.0 - Out-of-bounds Read in XLS Processing
CVSS 5.0
CVE-2026-6364
MEDIUM
Google Chrome < 147.0.7727.101 - Out-of-bounds Read in Skia
CVSS 6.5
CVE-2026-6308
HIGH
Google Chrome < 147.0.7727.101 - Out-of-bounds Read in Media
CVSS 7.5
CVE-2026-40917
MEDIUM
Gimp: gimp: application crashes or information disclosure via crafted icns image files
CVSS 5.0
CVE-2026-27294
HIGH
Adobe Framemaker | Out-of-bounds Read (CWE-125)
CVSS 7.8
CVE-2026-33019
HIGH
libsixel: Integer overflow leads to Out-of-bounds Read in img2sixel
CVSS 7.1
CVE-2026-27287
HIGH
InCopy | Out-of-bounds Read (CWE-125)
CVSS 7.8
CVE-2026-27289
HIGH
Photoshop Desktop | Out-of-bounds Read (CWE-125)
CVSS 7.8
CVE-2026-33822
MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 6.1
CVE-2026-33096
HIGH
Microsoft Windows HTTP.sys - Denial of Service
CVSS 7.5
CVE-2026-32188
HIGH
Microsoft Excel Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-32076
HIGH
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-27931
MEDIUM
Microsoft Windows GDI - Out-of-Bounds Read Information Disclosure
CVSS 5.5
CVE-2026-27930
MEDIUM
Microsoft Windows GDI - Out-of-Bounds Read Information Disclosure
CVSS 5.5
CVE-2026-26156
HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-26153
HIGH
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-27284
HIGH
InDesign Desktop | Out-of-bounds Read (CWE-125)
CVSS 7.8
CVE-2026-5713
MEDIUM
Out-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious target
CVE-2026-39979
MEDIUM
jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
CVSS 6.5
CVE-2026-39956
MEDIUM
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
CVSS 6.1
CVE-2026-33905
MEDIUM
ImageMagick -sample Operation - Out-of-Bounds Read
CVSS 5.5
CVE-2026-32605
HIGH
Nimiq: Remote crash via off-by-one signer bounds check in proposal buffer
CVSS 7.5
CVE-2026-30997
HIGH
FFmpeg < 8.0.1 - Denial of Service via read_global_param() Out-of-Bounds Read
CVSS 7.5
CVE-2026-25209
MEDIUM
Samsung Open Source Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335 - Out-of-bounds Read
CVSS 6.5
Details
Vulnerabilities
8,784