CWE-125

Out-of-bounds Read

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product reads data past the end, or before the beginning, of the intended buffer.

9,160 vulnerabilities with CWE-125
CVE-2026-56374 LOW
ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
CVSS 3.3
CVE-2026-56362 LOW
ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization
CVSS 3.3
CVE-2026-57258 MEDIUM
Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
CVSS 6.1
CVE-2026-57257 MEDIUM
Foxit PDF Editor/Reader PRC 3D BRep - Out-of-Bounds Read Denial of Service
CVSS 6.1
CVE-2026-57255 MEDIUM
Foxit PDF Editor/Reader Color Space - Out-of-Bounds Read Denial of Service
CVSS 6.1
CVE-2026-57253 MEDIUM
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
CVSS 6.1
CVE-2026-57243 MEDIUM
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVSS 6.1
CVE-2026-57241 MEDIUM
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVSS 6.1
CVE-2026-50811 MEDIUM
FreeType < 2.14.4 - Out-of-Bounds Read in TT_Get_Var_Design via GX Variation Handling
CVSS 6.5
CVE-2026-14740 CRITICAL
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
CVSS 9.1
CVE-2026-58469 HIGH
GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing
CVSS 7.5
CVE-2026-38973 MEDIUM
mrubyc <= 3.4.1 - Out-of-Bounds Read in Missing-Method Lookup via mrbc_find_method()
CVSS 4.4
CVE-2026-13705 HIGH
Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
CVSS 7.1
CVE-2026-10657 LOW
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
CVSS 3.7
CVE-2026-14647 MEDIUM
onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
CVSS 4.3
CVE-2026-53360 HIGH
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
CVSS 8.8
CVE-2026-56015 CRITICAL
Net::IP::LPM for Perl <= 1.10 - Heap Out-of-Bounds Read
CVSS 9.1
CVE-2026-38971 CRITICAL
ArduPilot Plane <= 4.6.3 - Out-of-Bounds Read in GCS_MAVLINK::handle_serial_control
CVSS 9.1
CVE-2026-14422 HIGH
Google Chrome - Out-of-Bounds Access
CVSS 8.8
CVE-2026-14420 CRITICAL
Google Chrome - Out-of-Bounds Access
CVSS 9.6
CVE-2026-14416 CRITICAL
Google Chrome - Out-of-bounds Read
CVSS 9.6
CVE-2026-14406 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 5.9
CVE-2026-14396 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-14388 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-14386 MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
Details
Vulnerabilities 9,160