CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,815 vulnerabilities with CWE-125
CVE-2026-24796 MEDIUM
CloverBootloader <5162 - Buffer Overflow
CVE-2026-22984 CRITICAL
Linux Kernel 5.11.0-6.18.6 - Out-of-bounds Read in libceph handle_auth_done()
CVSS 9.8
CVE-2026-23951 MEDIUM
SumatraPDF - Out-of-bounds Read in PalmDbReader Mobi File Handling
CVSS 5.5
CVE-2026-0899 HIGH
Google Chrome < 144.0.7559.59 - Out-of-bounds Read in V8
CVSS 8.8
CVE-2026-22859 CRITICAL
FreeRDP < 3.20.1 - Out-of-bounds Read in URBDRC Client
CVSS 9.1
CVE-2026-22858 CRITICAL
FreeRDP < 3.20.1 - Out-of-bounds Read via Base64 Decoding
CVSS 9.1
CVE-2026-22855 CRITICAL
FreeRDP < 3.20.1 - Out-of-bounds Read in Smartcard SetAttrib Path
CVSS 9.1
CVE-2026-21303 MEDIUM
Substance 3D Modeler < 1.22.5 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2026-21302 MEDIUM
Substance 3D Modeler < 1.22.5 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2026-21308 MEDIUM
Substance 3D Designer < 15.1.0 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2026-21278 MEDIUM
Adobe InDesign < 20.5.1 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2026-20946 HIGH
Microsoft Office Excel - Code Injection
CVSS 7.8
CVE-2026-20944 HIGH
Microsoft Office Word - Code Injection
CVSS 8.4
CVE-2026-20936 MEDIUM
Windows 10/11 NDIS Out-of-bounds Read Vulnerability
CVSS 4.3
CVE-2026-20851 MEDIUM
Capability Access Management Service - Info Disclosure
CVSS 6.2
CVE-2026-20835 MEDIUM
Capability Access Management Service - Info Disclosure
CVSS 5.5
CVE-2026-20829 MEDIUM
Windows TPM - Authenticated Out-of-bounds Read
CVSS 5.5
CVE-2026-20828 MEDIUM
Windows 10 1607-22H2 and Windows 11 23H2-25H2 - Unauthenticated Out-of-bounds Read in Internet Connection Sharing
CVSS 4.6
CVE-2026-22801 MEDIUM
libpng 1.6.26-1.6.53 - Heap Buffer Over-read via Negative Row Stride
CVSS 6.8
CVE-2026-22695 MEDIUM
libpng 1.6.51-1.6.53 - Heap Buffer Over-read in png_image_finish_read
CVSS 6.1
CVE-2026-22023 HIGH
CryptoLib < 1.4.3 - Out-of-bounds Read in cryptography_aead_encrypt()
CVSS 7.5
CVE-2026-21900 MEDIUM
CryptoLib < 1.4.3 - Out-of-bounds Read in cryptography_encrypt()
CVSS 5.9
CVE-2026-21899 MEDIUM
CryptoLib < 1.4.3 - Out-of-bounds Read in base64urlDecode
CVSS 4.7
CVE-2026-21898 HIGH
CryptoLib < 1.4.3 - Out-of-bounds Read in AOS Frame Hash Parsing
CVSS 8.2
CVE-2026-20973 MEDIUM
libimagecodec <SMR Jan-2026 Release 1 - Memory Corruption
CVSS 5.3
Details
Vulnerabilities 8,815