CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,159 vulnerabilities with CWE-125
CVE-2026-64685 MEDIUM
ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check
CVSS 5.3
CVE-2026-10684 LOW
Out-of-bounds read in coredump shell when printing stored-dump target code
CVSS 3.0
CVE-2026-17550 MEDIUM
DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVSS 5.5
CVE-2026-16465 MEDIUM
DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVSS 6.1
CVE-2026-58160 MEDIUM
Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
CVSS 6.5
CVE-2026-50735 MEDIUM
Enterprisedb Pglogical < 2.4.8 - Out-of-bounds Read
CVE-2026-42494 MEDIUM
buffer overruns in libfsimage iso9660 handling
CVSS 6.1
CVE-2026-17072 LOW
Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers
CVSS 3.3
CVE-2026-64776 MEDIUM
macOS < 14.8.8 / < 15.7.8 / < 26.6 - Kernel Memory Disclosure via Bounds Check Bypass
CVSS 5.5
CVE-2026-64768 HIGH
Apple Ios And iPadOS - Denial of Service
CVSS 8.1
CVE-2026-64762 CRITICAL
Apple macOS - Out-of-Bounds Access
CVSS 9.8
CVE-2026-64719 HIGH
Apple Safari - Denial of Service
CVSS 8.1
CVE-2026-64692 HIGH
Apple Ios And iPadOS - Denial of Service
CVSS 7.1
CVE-2026-43817 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43809 CRITICAL
Apple macOS - Out-of-Bounds Access
CVSS 9.8
CVE-2026-43773 CRITICAL
Apple macOS - Out-of-Bounds Access
CVSS 9.8
CVE-2026-43767 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Denial of Service via Memory Handling
CVSS 5.0
CVE-2026-43757 CRITICAL
Apple macOS - Out-of-Bounds Access
CVSS 9.8
CVE-2026-43753 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 4.6
CVE-2026-43747 HIGH
Apple macOS - Out-of-Bounds Access
CVSS 7.1
CVE-2026-43738 MEDIUM
macOS < 14.8.8 and < 15.7.8 - Process Memory Disclosure via Malicious Asset Catalog
CVSS 5.5
CVE-2026-66759 HIGH
Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images
CVSS 7.1
CVE-2026-66731 HIGH
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
CVSS 7.5
CVE-2026-66729 HIGH
facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
CVSS 7.5
CVE-2026-17572 MEDIUM
HDF5 SOHM List Index Heap Buffer Overflow
Details
Vulnerabilities 9,159