CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,790 vulnerabilities with CWE-125
CVE-2026-23388 HIGH
Squashfs: check metadata block offset is within range
CVSS 7.1
CVE-2026-23363 HIGH
wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23327 HIGH
cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
CVSS 7.1
CVE-2026-23325 HIGH
wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23318 HIGH
ALSA: usb-audio: Use correct version for UAC3 header validation
CVSS 7.1
CVE-2026-23315 HIGH
wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23305 HIGH
accel/rocket: fix unwinding in error path in rocket_probe
CVSS 7.1
CVE-2026-23288 HIGH
accel/amdxdna: Fix out-of-bounds memset in command slot handling
CVSS 7.8
CVE-2026-28890 MEDIUM
Xcode < 26.4 - Out-of-bounds Read
CVSS 5.5
CVE-2026-28859 MEDIUM
Safari < 26.4 - Out-of-bounds Read
CVSS 4.3
CVE-2026-28857 MEDIUM
Safari < 26.4 - Out-of-bounds Read via Malicious Web Content
CVSS 6.5
CVE-2026-28832 HIGH
macOS < 14.8.5, < 15.7.5, < 26.4 - Out-of-bounds Read
CVSS 8.4
CVE-2026-20690 MEDIUM
iOS and iPadOS < 18.7.7 - Out-of-bounds Read via Malicious Audio Stream
CVSS 6.5
CVE-2026-20657 MEDIUM
iOS and iPadOS < 18.7.7 - Buffer Overflow via Maliciously Crafted File
CVSS 6.5
CVE-2026-32853 HIGH
LibVNCServer UltraZip Encoding Heap Out-of-bounds Read
CVSS 8.1
CVE-2026-32647 HIGH
NGINX ngx_http_mp4_module vulnerability
CVSS 7.8
CVE-2026-4753 CRITICAL
Out-of-bounds Read in slajerek RetroDebugger
CVSS 9.1
CVE-2026-4750 CRITICAL
Out-of-bounds Read in fabiangreffrath woof
CVSS 9.1
CVE-2026-4744 CRITICAL
Notepad3 Bundled Oniguruma compile_string_node() Heap Buffer Overflow via Crafted Regex Pattern Allows Arbitrary Code Execution
CVE-2026-4732 HIGH
Out-of-bounds Read Overflow in tildearrow/furnace
CVE-2026-4677 HIGH
Google Chrome < 146.0.7680.165 - Out-of-bounds Read in WebAudio
CVSS 8.8
CVE-2026-4674 HIGH
Google Chrome < 146.0.7680.165 - Out-of-bounds Read in CSS
CVSS 8.8
CVE-2026-1940 MEDIUM
Gstreamer: incomplete fix of cve-2026-1940
CVSS 5.1
CVE-2026-3055 CRITICAL KEV
Insufficient input validation leading to memory overread
CVSS 9.8
CVE-2026-4647 MEDIUM
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
CVSS 6.1
Details
Vulnerabilities 8,790