CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,815 vulnerabilities with CWE-125
CVE-2025-71264 LOW
Mumble < 1.6.870 - Denial of Service via Out-of-bounds Array Access
CVSS 3.7
CVE-2025-15038 MEDIUM
ASUS Business System Control Interface - Info Disclosure
CVE-2025-70330 LOW
Easy Grade Pro 4.1.0.2 - Denial of Service via Crafted .EGP File Parsing
CVSS 3.3
CVE-2025-64736 MEDIUM
libbiosig 3.9.2 and Master Branch - Out-of-Bounds Read in ABF Parsing
CVSS 6.1
CVE-2025-14055 LOW
Silicon Labs Secure NCP - Buffer Overflow
CVE-2025-71231 HIGH
Linux Kernel < 6.12.72, 6.13.0-6.18.11, 6.19.0-6.19.1, 6.8.0-6.12.72 - Out-of-bounds Read in IAA Compression
CVSS 7.1
CVE-2025-71201 HIGH
Linux Kernel 6.14-6.18.5 - Out-of-bounds Read in netfs Read Unlock Mechanism
CVSS 7.1
CVE-2025-70121 HIGH
free5gc 4.0.1 - Denial of Service via NAS Registration Request 5GS Mobile Identity
CVSS 7.5
CVE-2025-69806 HIGH
p2r3 bareiron - Unauthenticated Out-of-bounds Read via Network Packet
CVSS 7.5
CVE-2025-54170 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Out-of-bounds Read
CVSS 6.5
CVE-2025-54169 MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5067 - Authenticated Out-of-bounds Read
CVSS 6.5
CVE-2025-32007 MEDIUM
Intel TDX Module < 1.5.24 - Out-of-bounds Read in Ring 0 Hypervisor
CVSS 4.4
CVE-2025-32003 MEDIUM
Intel(R) Ethernet Network Adapter E810 <cvl fw 1.7.6, cpk 1.3.7 - DoS
CVSS 6.5
CVE-2025-27940 MEDIUM
TDX Module <tdx1.5 - Info Disclosure
CVSS 4.1
CVE-2025-27708 MEDIUM
Intel(R) CSME Firmware - Info Disclosure
CVSS 4.1
CVE-2025-65081 MEDIUM
Lexmark - Memory Corruption
CVE-2025-64098 MEDIUM
Fast DDS < 2.6.11 - Denial of Service via Tampered DATA Submessage in SPDP Packet
CVSS 5.9
CVE-2025-62603 HIGH
Fast DDS < 2.6.11 - Out-of-bounds Read in ParticipantGenericMessage CDR Parser
CVSS 7.5
CVE-2025-47402 MEDIUM
Qualcomm SA8620P and other Snapdragon Firmware - Denial of Service via Large Authentication Information Element
CVSS 6.5
CVE-2025-63657 HIGH
monkey < 1.8.5 - Denial of Service via Crafted HTTP Request in mk_mimetype_find
CVSS 7.5
CVE-2025-63656 HIGH
monkey < 1.8.5 - Denial of Service via Header Comparison Out-of-Bounds Read
CVSS 7.5
CVE-2025-63653 HIGH
monkey < 1.8.5 - Denial of Service via Out-of-bounds Read in mk_vhost_fdt_close
CVSS 7.5
CVE-2025-63650 HIGH
monkey < 1.8.5 - Denial of Service via Crafted HTTP Request in mk_ptr_to_buf
CVSS 7.5
CVE-2025-63649 HIGH
monkey < 1.8.5 - Denial of Service via Chunked Transfer-Encoding HTTP Parser
CVSS 7.5
CVE-2025-71004 MEDIUM
OneFlow v0.9.0 - Denial of Service via Segmentation Violation in Logical Or Component
CVSS 6.5
Details
Vulnerabilities 8,815