CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,159 vulnerabilities with CWE-125
CVE-2026-59145 CRITICAL
Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find
CVSS 9.1
CVE-2026-59143 MEDIUM
Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked
CVSS 6.3
CVE-2026-46600 HIGH
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVSS 7.5
CVE-2026-59142 CRITICAL
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy
CVSS 9.1
CVE-2026-59141 CRITICAL
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked
CVSS 9.1
CVE-2026-59140 CRITICAL
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths
CVSS 9.1
CVE-2026-59139 CRITICAL
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked
CVSS 9.1
CVE-2026-12548 MEDIUM
Libsoup: heap out-of-bounds read in libsoup due to integer truncation
CVSS 4.2
CVE-2026-16243 MEDIUM
Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero
CVE-2026-9499 MEDIUM
Out-of-bounds read in QTextCodec::codecForName() in Qt
CVE-2026-59842 LOW
Libssh: libssh: information disclosure via short gssapi curve25519 public key
CVSS 3.7
CVE-2026-64609 CRITICAL
Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
CVSS 9.1
CVE-2026-15903 HIGH
Google Chrome - Out-of-Bounds Access
CVSS 8.8
CVE-2026-55639 MEDIUM
xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)
CVSS 5.3
CVE-2026-55645 MEDIUM
xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)
CVSS 6.5
CVE-2026-44978 MEDIUM
xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification
CVSS 5.3
CVE-2026-35217 MEDIUM
NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds Read
CVSS 6.5
CVE-2026-26197 HIGH
Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
CVSS 7.5
CVE-2026-16254 MEDIUM
Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser
CVSS 4.3
CVE-2026-63807 HIGH
KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVSS 8.8
CVE-2026-63799 HIGH
sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
CVSS 7.8
CVE-2026-63796 HIGH
ocfs2: reject oversized group bitmap descriptors
CVSS 8.8
CVE-2026-53402 HIGH
fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVSS 7.1
CVE-2026-53390 HIGH
ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVSS 8.1
CVE-2026-16013 MEDIUM
liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
CVSS 5.3
Details
Vulnerabilities 9,159