CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,160 vulnerabilities with CWE-125
CVE-2026-54988 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVSS 6.1
CVE-2026-54111 HIGH
Microsoft Windows 11 Version 24H2 - Universal Print Management Service Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-54058 HIGH
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
CVE-2026-50300 MEDIUM
Microsoft Windows 10 Version 1607 - Windows DWM Core Library Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-49794 MEDIUM
Microsoft Windows 10 Version 1607 - Windows USB Audio Class Driver Information Disclosure Vulnerability
CVSS 4.6
CVE-2026-60082 CRITICAL
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVSS 9.1
CVE-2026-59198 MEDIUM
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVSS 6.5
CVE-2026-10672 HIGH
Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
CVSS 8.2
CVE-2026-53566 MEDIUM
Citrix Secure Access Client For Windows < 26.6.1.20 - Out-of-Bounds Access
CVE-2026-12478 MEDIUM
Red Hat Enterprise Linux 10 libsoup - Out-of-Bounds Read
CVSS 4.8
CVE-2026-58102 CRITICAL
Perl Crypt::OpenSSL::X509 < 2.1.3 - Heap Out-of-Bounds Read
CVSS 9.1
CVE-2026-51541 CRITICAL
OpENer 2.3.0 - Out-of-Bounds Read in CIP Message Parsing via Forged EPath Size
CVSS 9.1
CVE-2026-51537 CRITICAL
EIPStackGroup OpENer 2.3.0 - Unauthenticated Out-of-Bounds Read via Malformed CIP ForwardOpen Request
CVSS 9.1
CVE-2026-60103 MEDIUM
Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block
CVSS 6.1
CVE-2026-57432 HIGH
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
CVSS 8.4
CVE-2026-57158 CRITICAL
FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530
CVSS 9.1
CVE-2026-57157 MEDIUM
Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName
CVSS 6.5
CVE-2026-14461 MEDIUM
mtr <= 0.96 - DNS TXT Response Out-of-Bounds Read
CVE-2026-40454 HIGH
Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
CVSS 7.5
CVE-2026-11404 HIGH
Cesanta Mongoose < 7.22 Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing
CVSS 7.5
CVE-2026-15185 LOW
GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
CVSS 3.3
CVE-2026-58307 MEDIUM
Samsung Open Source Escargot - Out-of-bounds Read
CVSS 6.1
CVE-2026-58304 MEDIUM
Samsung Open Source Escargot - Out-of-bounds Read
CVSS 6.1
CVE-2026-15114 HIGH
Google Chrome - Out-of-Bounds Access
CVSS 8.8
CVE-2026-29007 MEDIUM
U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
CVSS 5.3
Details
Vulnerabilities 9,160