CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

8,471 vulnerabilities with CWE-125
CVE-2026-34588 HIGH
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
CVSS 7.8
CVE-2026-5673 MEDIUM
Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing
CVSS 5.6
CVE-2026-34776 MEDIUM
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
CVSS 5.3
CVE-2026-34824 HIGH
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVSS 7.5
CVE-2026-28815 HIGH
Apple Macos < 4.3.1 - Out-of-Bounds Access
CVSS 7.5
CVE-2026-34608 MEDIUM
nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read
CVSS 4.9
CVE-2026-35038 MEDIUM
signalk-server: Arbitrary Prototype Read via `from` Field Bypass
CVSS 6.5
CVE-2026-34876 HIGH
Mbed TLS 3.x <3.6.6 - Info Disclosure
CVSS 7.5
CVE-2026-5342 MEDIUM
LibRaw TIFF/NEF decoders_libraw.cpp nikon_load_padded_packed_raw out-of-bounds
CVSS 5.3
CVE-2026-5315 MEDIUM
Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds
CVSS 4.3
CVE-2026-5314 MEDIUM
Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds
CVSS 4.3
CVE-2026-32929 HIGH
Fuji Electric Co., Ltd. / Hakko Electronics Co., Ltd. V-sft < 6.2.10.0 and prior - Information Disclosure
CVSS 7.8
CVE-2026-32927 HIGH
Fuji Electric Co., Ltd. / Hakko Electronics Co., Ltd. V-sft < 6.2.10.0 and prior - Information Disclosure
CVSS 7.8
CVE-2026-32926 HIGH
Fuji Electric Co., Ltd. / Hakko Electronics Co., Ltd. V-sft < 6.2.10.0 and prior - Information Disclosure
CVSS 7.8
CVE-2026-23406 HIGH
apparmor: fix side-effect bug in match_char() macro usage
CVSS 7.8
CVE-2026-5292 HIGH
Google Chrome < 146.0.7680.178 - Out-of-Bounds Access
CVSS 8.8
CVE-2026-5282 HIGH
Google Chrome < 146.0.7680.178 - Out-of-Bounds Access
CVSS 8.1
CVE-2026-2394 MEDIUM
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
CVSS 6.5
CVE-2026-34556 MEDIUM
iccDEV: HBO in icAnsiToUtf8()
CVSS 6.2
CVE-2026-34554 MEDIUM
iccDEV: HBO in CIccApplyCmmSearch::costFunc()
CVSS 6.2
CVE-2026-34235 CRITICAL
PJSIP: Heap OOB read in VPX unpacketizer
CVSS 9.1
CVE-2026-33985 MEDIUM
FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
CVSS 5.9
CVE-2026-33982 HIGH
FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read
CVSS 7.1
CVE-2026-32877 HIGH
Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field
CVSS 8.2
CVE-2026-25627 MEDIUM
nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket
CVSS 6.5
Details
Vulnerabilities 8,471