CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,784 vulnerabilities with CWE-125
CVE-2026-25206 MEDIUM
Samsung Open Source Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335 - Out-of-bounds Read
CVSS 6.7
CVE-2026-31413 HIGH
bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR
CVSS 7.8
CVE-2026-5393 CRITICAL
OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS
CVSS 9.1
CVE-2026-5392 MEDIUM
wolfSSL heap OOB read in PKCS7 SignedData streaming
CVSS 5.4
CVE-2026-34987 CRITICAL
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
CVSS 9.9
CVE-2026-34971 HIGH
Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
CVSS 7.8
CVE-2026-34941 HIGH
Wasmtime Component Model String Transcoding - Heap Out-of-Bounds Read
CVSS 8.1
CVE-2026-39856 MEDIUM
osslsigncode <2.13 PE Section Bounds - Out-of-Bounds Read
CVSS 5.5
CVE-2026-39855 MEDIUM
osslsigncode <2.13 PE Page Hashing - Out-of-Bounds Read
CVSS 5.5
CVE-2026-5445 CRITICAL
Out-of-Bounds Read in DicomImageDecoder (DecodeLookupTable)
CVSS 9.1
CVE-2026-5441 HIGH
Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)
CVSS 7.1
CVE-2026-5437 HIGH
Orthanc DICOM Server - Out-of-bounds Read in DicomStreamReader
CVSS 7.5
CVE-2026-5913 HIGH
Google Chrome < 147.0.7727.55 - Out-of-bounds Read in Blink
CVSS 8.1
CVE-2026-5907 HIGH
Google Chrome < 147.0.7727.55 - Out-of-bounds Read via Crafted Video File
CVSS 8.1
CVE-2026-5886 MEDIUM
Google Chrome < 147.0.7727.55 - Out-of-bounds Read in WebAudio
CVSS 5.3
CVE-2026-5873 HIGH
Google Chrome < 147.0.7727.55 - Out-of-bounds Read and Write in V8
CVSS 8.8
CVE-2026-40026 MEDIUM
Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
CVSS 4.4
CVE-2026-40025 MEDIUM
Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
CVSS 4.4
CVE-2026-39864 MEDIUM
Kamailio Auth: Processing Vulnerability For Additional Authenticated User Identity Checks
CVSS 4.4
CVE-2026-28386 HIGH
OpenSSL 3.6.0-3.6.1 - Denial of Service via AES-CFB128 Partial Block Processing
CVSS 7.5
CVE-2026-32864 HIGH
NI LabVIEW Out-of-bounds Read in mgcore_SH_25_3!aligned_free()
CVSS 7.8
CVE-2026-32863 HIGH
Out-of-Bounds Read in sentry_transaction_context_set_operation()
CVSS 7.8
CVE-2026-5735 CRITICAL
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
CVSS 9.8
CVE-2026-35444 HIGH
SDL_image XCF Loader - Heap Out-of-Bounds Read
CVSS 7.1
CVE-2026-35203 HIGH
ZLMediaKit VP9 RTP Parser Out-of-Bounds Read
CVSS 7.5
Details
Vulnerabilities 8,784