CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,790 vulnerabilities with CWE-125
CVE-2026-4437 HIGH
gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
CVSS 7.5
CVE-2026-33069 HIGH
PJSIP <2.17 SIP Multipart Parsing - Out-of-Bounds Read
CVSS 7.5
CVE-2026-4462 HIGH
Google Chrome < 146.0.7680.153 - Out-of-bounds Read in Blink via Crafted HTML Page
CVSS 8.8
CVE-2026-4460 HIGH
Google Chrome < 146.0.7680.153 - Out-of-bounds Read in Skia via Crafted HTML Page
CVSS 8.8
CVE-2026-4459 HIGH
Google Chrome < 146.0.7680.153 - Out-of-bounds Read and Write in WebAudio
CVSS 8.8
CVE-2026-4440 HIGH
Google Chrome < 146.0.7680.153 - Out-of-bounds Read and Write in WebGL
CVSS 8.8
CVE-2026-4439 HIGH
Google Chrome < 146.0.7680.153 - Out-of-bounds Read in WebGL
CVSS 8.8
CVE-2026-4159 LOW
wc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read
CVSS 3.3
CVE-2026-3547 HIGH
wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
CVSS 7.5
CVE-2026-4424 HIGH
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
CVSS 7.5
CVE-2026-31967 CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31966 CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31965 HIGH
HTSlib CRAM reader has out-of-bounds reads due to improper validation of input
CVSS 8.2
CVE-2026-31962 HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.8
CVE-2026-23269 HIGH
apparmor: validate DFA start states are in bounds in unpack_pdb
CVSS 7.1
CVE-2026-23244 HIGH
nvme: fix memory allocation in nvme_pr_read_keys()
CVSS 7.1
CVE-2026-22882 MEDIUM
Canva Affinity < 3.1.0 - Out-of-bounds Read via EMF File
CVSS 6.1
CVE-2026-20726 MEDIUM
Canva Affinity < 3.1.0 - Out-of-bounds Read via EMF File
CVSS 6.1
CVE-2026-0708 HIGH
Libucl: libucl: denial of service via embedded null byte in ucl input
CVSS 8.3
CVE-2026-4227 HIGH
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
CVSS 8.8
CVE-2026-3442 MEDIUM
Red Hat Enterprise Linux 10 - Buffer Overflow
CVSS 6.1
CVE-2026-3441 MEDIUM
Binutils: gnu binutils: information disclosure via specially crafted xcoff object file
CVSS 6.1
CVE-2026-28521 HIGH
arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure
CVSS 7.7
CVE-2026-32320 MEDIUM
Ella Core < 1.5.1 - Unauthenticated Denial of Service via NGAP PathSwitchRequest
CVSS 6.5
CVE-2026-32319 HIGH
Ella Core < 1.5.1 - Unauthenticated Denial of Service via Malformed NGAP/NAS Message
CVSS 7.5
Details
Vulnerabilities 8,790