CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,159 vulnerabilities with CWE-125
CVE-2026-44452 MEDIUM
h2o is vulnerable to heap overrun
CVSS 5.9
CVE-2026-57077 HIGH
YAML::Syck < 1.47 - newline_len Out-of-Bounds Read
CVSS 7.7
CVE-2026-57075 CRITICAL
YAML::Syck < 1.47 - syck_base64dec Out-of-Bounds Read
CVSS 9.1
CVE-2026-60073 MEDIUM
AutomationDirect Productivity Suite Out-of-bounds Read
CVSS 5.9
CVE-2026-57896 MEDIUM
AutomationDirect Productivity Suite Out-of-bounds Read
CVSS 6.1
CVE-2026-60140 MEDIUM
AutomationDirect Productivity Suite Out-of-bounds Read
CVSS 6.1
CVE-2026-57074 CRITICAL
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
CVSS 9.1
CVE-2026-57073 CRITICAL
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
CVSS 9.1
CVE-2026-47729 MEDIUM
Squid: Memory disclosure in FTP gateway
CVSS 6.5
CVE-2026-45612 MEDIUM
rz-libdemangle: Out of bound read in rust demangler
CVSS 5.5
CVE-2026-38754 MEDIUM
Busybox 1.38.0 - Denial of Service via Heap Overflow in ifsbreakup Function
CVSS 5.1
CVE-2026-62353 MEDIUM
TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken
CVSS 5.4
CVE-2026-62351 HIGH
TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg
CVSS 7.5
CVE-2026-10673 HIGH
Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
CVSS 8.3
CVE-2026-60065 LOW
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
CVSS 3.7
CVE-2026-61862 LOW
ImageMagick before 7.1.2-26 Information Disclosure via identify
CVSS 2.9
CVE-2026-15030 MEDIUM
Asus System Control Interface v3 - Out-of-bounds Read
CVE-2026-47979 MEDIUM
Media Encoder | Out-of-bounds Read (CWE-125)
CVSS 5.5
CVE-2026-15714 MEDIUM
Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
CVSS 6.5
CVE-2026-15720 HIGH
open5gs < 2.7.7 - Denial of Service
CVSS 8.6
CVE-2026-15712 MEDIUM
Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
CVSS 5.9
CVE-2026-58539 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Remote Desktop Client Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-58529 HIGH
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-58528 MEDIUM
Microsoft Windows 10 Version 1809 - Windows USB Audio Class Driver Information Disclosure Vulnerability
CVSS 6.8
CVE-2026-57094 HIGH
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVSS 8.8
Details
Vulnerabilities 9,159