CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
9,160 vulnerabilities with CWE-125
CVE-2026-56374
LOW
ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
CVSS 3.3
CVE-2026-56362
LOW
ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization
CVSS 3.3
CVE-2026-57258
MEDIUM
Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
CVSS 6.1
CVE-2026-57257
MEDIUM
Foxit PDF Editor/Reader PRC 3D BRep - Out-of-Bounds Read Denial of Service
CVSS 6.1
CVE-2026-57255
MEDIUM
Foxit PDF Editor/Reader Color Space - Out-of-Bounds Read Denial of Service
CVSS 6.1
CVE-2026-57253
MEDIUM
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
CVSS 6.1
CVE-2026-57243
MEDIUM
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVSS 6.1
CVE-2026-57241
MEDIUM
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVSS 6.1
CVE-2026-50811
MEDIUM
FreeType < 2.14.4 - Out-of-Bounds Read in TT_Get_Var_Design via GX Variation Handling
CVSS 6.5
CVE-2026-14740
CRITICAL
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
CVSS 9.1
CVE-2026-58469
HIGH
GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing
CVSS 7.5
CVE-2026-38973
MEDIUM
mrubyc <= 3.4.1 - Out-of-Bounds Read in Missing-Method Lookup via mrbc_find_method()
CVSS 4.4
CVE-2026-13705
HIGH
Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
CVSS 7.1
CVE-2026-10657
LOW
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
CVSS 3.7
CVE-2026-14647
MEDIUM
onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
CVSS 4.3
CVE-2026-53360
HIGH
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
CVSS 8.8
CVE-2026-56015
CRITICAL
Net::IP::LPM for Perl <= 1.10 - Heap Out-of-Bounds Read
CVSS 9.1
CVE-2026-38971
CRITICAL
ArduPilot Plane <= 4.6.3 - Out-of-Bounds Read in GCS_MAVLINK::handle_serial_control
CVSS 9.1
CVE-2026-14422
HIGH
Google Chrome - Out-of-Bounds Access
CVSS 8.8
CVE-2026-14420
CRITICAL
Google Chrome - Out-of-Bounds Access
CVSS 9.6
CVE-2026-14416
CRITICAL
Google Chrome - Out-of-bounds Read
CVSS 9.6
CVE-2026-14406
MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 5.9
CVE-2026-14396
MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-14388
MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
CVE-2026-14386
MEDIUM
Google Chrome - Out-of-bounds Read
CVSS 6.5
Details
Vulnerabilities
9,160