CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
9,161 vulnerabilities with CWE-125
CVE-2026-9875
CRITICAL
Google Chrome - Out-of-bounds Read
CVSS 9.6
CVE-2026-10017
HIGH
Google Chrome - Out-of-bounds Read
CVSS 8.3
CVE-2026-39929
HIGH
Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP
CVSS 7.5
CVE-2026-47333
HIGH
Out-of-bounds read in Ubuntu Linux AppArmor notification handling
CVSS 7.8
CVE-2026-47332
MEDIUM
Out-of-bounds read in Ubuntu Linux AppArmor notification handling
CVSS 5.5
CVE-2026-46230
HIGH
drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
CVSS 7.1
CVE-2026-46204
HIGH
drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVSS 7.1
CVE-2026-46203
HIGH
spi: cadence-quadspi: fix unclocked access on unbind
CVSS 7.1
CVE-2026-46199
HIGH
drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
CVSS 7.1
CVE-2026-46191
HIGH
fbcon: Avoid OOB font access if console rotation fails
CVSS 7.1
CVE-2026-46190
HIGH
Linux - Out-of-Bounds Access
CVSS 7.1
CVE-2026-46185
CRITICAL
smb/client: fix out-of-bounds read in symlink_data()
CVSS 9.1
CVE-2026-46155
CRITICAL
smb/client: fix out-of-bounds read in smb2_compound_op()
CVSS 9.1
CVE-2026-46140
HIGH
Bluetooth: btmtk: validate WMT event SKB length before struct access
CVSS 7.1
CVE-2026-46138
HIGH
Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt
CVSS 8.1
CVE-2026-46133
HIGH
RDMA/rxe: Reject unknown opcodes before ICRC processing
CVSS 7.5
CVE-2026-46130
HIGH
dm-verity-fec: fix reading parity bytes split across blocks (take 3)
CVSS 7.1
CVE-2026-46119
CRITICAL
libceph: Fix slab-out-of-bounds access in auth message processing
CVSS 9.1
CVE-2026-9803
MEDIUM
Keycloak: keycloak: denial of service via malformed authorization header
CVSS 5.3
CVE-2026-47104
MEDIUM
libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()
CVSS 4.0
CVE-2026-46094
HIGH
ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
CVSS 7.1
CVE-2026-46078
HIGH
erofs: fix the out-of-bounds nameoff handling for trailing dirents
CVSS 7.1
CVE-2026-46067
HIGH
mm/damon/core: validate damos_quota_goal->nid for node_memcg_{used,free}_bp
CVSS 7.1
CVE-2026-46064
HIGH
ibmasm: fix heap over-read in ibmasm_send_i2o_message()
CVSS 7.1
CVE-2026-46033
HIGH
crypto: authencesn - reject short ahash digests during instance creation
CVSS 7.1
Details
Vulnerabilities
9,161