CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,823 vulnerabilities with CWE-125
CVE-2025-43584 MEDIUM
Substance 3D Viewer < 0.25 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2025-47135 MEDIUM
Adobe Dimension < 4.1.3 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2025-49696 HIGH
Microsoft 365 Apps and Office - Out-of-bounds Read
CVSS 8.4
CVE-2025-49689 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Local Privilege Escalation via VHDX Integer Overflow
CVSS 7.8
CVE-2025-49687 HIGH
Windows 10/11, Server 2012-2016 Privilege Escalation via IME Out-of-bounds Read
CVSS 8.8
CVE-2025-49681 MEDIUM
Windows Server RRAS Unauthenticated Out-of-bounds Read
CVSS 6.5
CVE-2025-49671 MEDIUM
Windows Server 2008/2012/2016/2019/2022/2025 Information Disclosure via RRAS
CVSS 6.5
CVE-2025-49658 MEDIUM
Windows TDX.sys - Authenticated Out-of-bounds Read
CVSS 5.5
CVE-2025-49657 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-48822 HIGH
Windows Hyper-V - Memory Corruption
CVSS 8.6
CVE-2025-48816 HIGH
Microsoft Windows HID Class Driver - Privilege Escalation
CVSS 7.8
CVE-2025-48812 MEDIUM
Microsoft Office Excel - Info Disclosure
CVSS 5.5
CVE-2025-48002 MEDIUM
Windows 11 24H2 and Windows Server 2025 < 10.0.26100.4652 - Authenticated Information Disclosure via Integer Overflow
CVSS 5.7
CVE-2025-47996 HIGH
Windows 10/11, Server 2008 - Privilege Escalation via MBT Transport Driver Integer Underflow
CVSS 7.8
CVE-2025-47978 MEDIUM
Windows Server 2022 - Denial of Service via Out-of-bounds Read in Kerberos
CVSS 6.5
CVE-2025-43587 MEDIUM
After Effects < 24.6.7 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2025-21168 MEDIUM
Substance 3D Designer < 14.1.1 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2025-21167 MEDIUM
Substance 3D Designer < 14.1.1 - Out-of-bounds Read via Malicious File
CVSS 5.5
CVE-2025-27057 HIGH
Qualcomm Wi-Fi Firmware - Denial of Service via Invalid Beacon Frame IE Header
CVSS 7.5
CVE-2025-27055 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2025-21454 HIGH
Qualcomm Firmware - Denial of Service via Beacon Frame Processing
CVSS 7.5
CVE-2025-21449 HIGH
Qualcomm Snapdragon and Smart Audio Platform Firmware - Denial of Service via Malformed SSID IE Length Field
CVSS 7.5
CVE-2025-21446 HIGH
Qualcomm FastConnect and Immersive Home Firmware - Denial of Service via WLAN Frame BTM Request Parsing
CVSS 7.5
CVE-2025-21427 HIGH
Qualcomm Snapdragon and Smart Display Firmware - Out-of-bounds Read in RTP Packet Payload Decoding
CVSS 8.2
CVE-2025-40740 HIGH
Siemens Solid Edge SE2025 < V225.0 Update 5 - Out-of-Bounds Read in PAR File Parser
CVSS 7.8
Details
Vulnerabilities 8,823