CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,817 vulnerabilities with CWE-125
CVE-2025-64893 HIGH
DNG SDK < 1.7.0 - Out-of-bounds Read via Malicious File
CVSS 7.1
CVE-2025-62572 HIGH
Windows 11 24H2/25H2 and Windows Server 2025 - Authenticated Privilege Escalation via Out-of-bounds Read
CVSS 7.8
CVE-2025-62564 HIGH
Microsoft Excel - Out-of-bounds Read
CVSS 7.8
CVE-2025-62468 MEDIUM
Windows 11 22H2-25H2 and Windows Server 2022-2025 - Authenticated Information Disclosure via Out-of-bounds Read
CVSS 5.5
CVE-2025-62457 HIGH
Windows Cloud Files Mini Filter Driver - Out-of-bounds Read
CVSS 7.8
CVE-2025-55233 HIGH
Windows Projected File System - Privilege Escalation
CVSS 7.8
CVE-2025-59391 MEDIUM
libcoap < 4.3.5a - Out-of-bounds Read in OSCORE Configuration Parser
CVSS 6.5
CVE-2025-48622 MEDIUM
Google Android - Out of Bounds Read in ProcessArea
CVSS 5.5
CVE-2025-48596 HIGH
Android - Out-of-bounds Read in Parcel.cpp
CVSS 7.8
CVE-2025-48592 HIGH
Android - Out-of-bounds Read in C2SoftDav1dDec.cpp
CVSS 7.5
CVE-2025-66624 HIGH
BACnet Protocol Stack <1.5.0.rc2 - Buffer Overflow
CVSS 7.5
CVE-2025-14104 MEDIUM
util-linux < 2.41.3 - Heap Buffer Overread in setpwnam()
CVSS 6.1
CVE-2025-66293 HIGH
libpng < 1.6.52 - Out-of-bounds Read in Simplified API
CVSS 7.1
CVE-2025-66409 CRITICAL
Espressif IOT Dev Framework <5.5.1-5.2.6 - Memory Corruption
CVSS 9.1
CVE-2025-58113 MEDIUM
PDF-XChange Editor 10.7.3.401 - Out-of-bounds Read in EMF Functionality
CVSS 6.5
CVE-2025-11789 HIGH
Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 - Out-of-bounds Read in DownloadFile Function
CVSS 7.5
CVE-2025-20776 MEDIUM
Android - Out-of-bounds Read in Display Component
CVSS 6.7
CVE-2025-20768 HIGH
Android - Out-of-Bounds Read in Display Component
CVSS 7.8
CVE-2025-20759 MEDIUM
MediaTek NR15 and NR16 - Out-of-bounds Read in Modem
CVSS 6.5
CVE-2025-58479 MEDIUM
libimagecodec.quram.so <SMR Dec-2025 Release 1 - Memory Corruption
CVSS 4.3
CVE-2025-58476 MEDIUM
Bootloader <SMR Dec-2025 Release 1 - Memory Corruption
CVSS 4.2
CVE-2025-8351 HIGH
Avast Antivirus <8.3.70.98 - Buffer Overflow
CVSS 7.8
CVE-2025-10101 HIGH
Avast Antivirus <3.9.2025 - Buffer Overflow
CVSS 7.8
CVE-2025-63523 MEDIUM
FeehiCMS 2.1.1 - Authenticated Parameter Tampering via Read-Only Field Bypass
CVSS 6.5
CVE-2025-41739 MEDIUM
CODESYS Control - Out-of-Bounds Read
CVSS 5.9
Details
Vulnerabilities 8,817