CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,790 vulnerabilities with CWE-125
CVE-2026-20424 MEDIUM
Android - Local Information Disclosure via Out-of-Bounds Read in Display Component
CVSS 4.4
CVE-2026-3391 LOW
FascinatedBox lily <2.3 - Memory Corruption
CVSS 3.3
CVE-2026-3390 LOW
FascinatedBox lily <=2.3 - Memory Corruption
CVSS 3.3
CVE-2026-3386 LOW
wren-lang wren <=0.4.0 - Memory Corruption
CVSS 3.3
CVE-2026-28420 MEDIUM
Vim < 9.2.0076 - Heap-based Buffer Overflow in Terminal Emulator
CVSS 4.4
CVE-2026-28419 MEDIUM
vim < 9.2.0075 - Heap-Based Buffer Underflow in Emacs-Style Tags File Parser
CVSS 5.3
CVE-2026-28418 MEDIUM
Vim < 9.2.0074 - Heap-based Buffer Overflow in Emacs-style Tags File Parser
CVSS 4.4
CVE-2026-28231 CRITICAL
pillow_heif <1.3.0 - Memory Corruption
CVSS 9.1
CVE-2026-22717 LOW
VMware Workstation <25H1 - Info Disclosure
CVSS 2.7
CVE-2026-3285 LOW
berry-lang berry <=1.1.0 - Memory Corruption
CVSS 3.3
CVE-2026-3283 LOW
libvips 8.19.0 - Out-of-bounds Read in vips_extract_band_build
CVSS 3.3
CVE-2026-3282 LOW
libvips 8.19.0 - Out-of-bounds Read in vips_unpremultiply_build
CVSS 3.3
CVE-2026-27831 HIGH
rldns 1.3 - Denial of Service via Heap-Based Out-of-Bounds Read
CVSS 7.5
CVE-2026-27798 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 4.0
CVE-2026-27711 MEDIUM
NanaZip 5.0.1252.0-6.0.1637.0 - Memory Corruption
CVSS 6.6
CVE-2026-27709 MEDIUM
NanaZip 5.0.1252.0-6.0.1637.0 - Info Disclosure
CVSS 6.6
CVE-2026-25942 HIGH
FreeRDP <3.23.0 - Memory Corruption
CVSS 7.5
CVE-2026-25941 MEDIUM
FreeRDP 2.0.0-2.11.7 - Out-of-bounds Read via RDPGFX WIRE_TO_SURFACE_2 PDU
CVSS 4.3
CVE-2026-27692 HIGH
iccDEV <=2.3.1.4 - Memory Corruption
CVSS 7.1
CVE-2026-0402 MEDIUM
SonicOS < 7.3.2-7010 - Authenticated Out-of-bounds Read
CVSS 4.9
CVE-2026-2771 CRITICAL
Firefox <115.33.0, 140.8-140.*, <148.0, >=148; Thunderbird <140.8.0, <148.0, >=148 - Out-of-bounds Read
CVSS 9.8
CVE-2026-2664 HIGH
Docker Desktop <=4.61.0 - Memory Corruption
CVSS 7.8
CVE-2026-26284 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25987 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 5.3
CVE-2026-25982 MEDIUM
ImageMagick <7.1.2-15/<6.9.13-40 - Memory Corruption
CVSS 6.5
Details
Vulnerabilities 8,790