CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,784 vulnerabilities with CWE-125
CVE-2026-2394 MEDIUM
RTI Connext Professional Core Libraries - Buffer Over-Read
CVSS 6.5
CVE-2026-34556 MEDIUM
iccDEV: HBO in icAnsiToUtf8()
CVSS 6.2
CVE-2026-34554 MEDIUM
iccDEV: HBO in CIccApplyCmmSearch::costFunc()
CVSS 6.2
CVE-2026-34235 CRITICAL
PJSIP: Heap OOB read in VPX unpacketizer
CVSS 9.1
CVE-2026-33985 MEDIUM
FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
CVSS 5.9
CVE-2026-33982 HIGH
FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read
CVSS 7.1
CVE-2026-32877 HIGH
Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field
CVSS 8.2
CVE-2026-25627 MEDIUM
nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket
CVSS 6.5
CVE-2026-28528 MEDIUM
BlueKitchen BTstack < 1.8.1 AVRCP Browsing Target GET_FOLDER_ITEMS Handler OOB Read / Undefined Behavior
CVSS 4.6
CVE-2026-28527 LOW
BlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB Read
CVSS 3.5
CVE-2026-28526 LOW
BlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB Read
CVSS 3.5
CVE-2026-32984 LOW
Heap buffer overflow in wazuh-authd
CVSS 3.5
CVE-2026-27880 HIGH
OpenFeature evaluation API reads input data with no bounds
CVSS 7.5
CVE-2026-33669 CRITICAL
SiYuan has Arbitrary Document Reading within the Publishing Service
CVSS 9.8
CVE-2026-3622 HIGH
Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N
CVSS 7.5
CVE-2026-32284 HIGH
Denial of service in github.com/shamaton/msgpack
CVSS 7.5
CVE-2026-33636 HIGH
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
CVSS 7.6
CVE-2026-26008 HIGH
EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes
CVSS 7.5
CVE-2026-33515 MEDIUM
Squid has issues in ICP message handling
CVSS 6.5
CVE-2026-23388 HIGH
Squashfs: check metadata block offset is within range
CVSS 7.1
CVE-2026-23363 HIGH
wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23327 HIGH
cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
CVSS 7.1
CVE-2026-23325 HIGH
wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23318 HIGH
ALSA: usb-audio: Use correct version for UAC3 header validation
CVSS 7.1
CVE-2026-23315 HIGH
wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()
CVSS 7.1
Details
Vulnerabilities 8,784