← Back
CWE-125

9,126 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,126)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jun 17, 2026
Feb 11, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Internet Connection Sharing (ICS) Denial of Service Vulnerability
1Microsoft
2Windows 11 24h2
Windows Server 2025
Jun 17, 2026
Feb 11, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
DHCP Client Service Denial of Service Vulnerability
1Adobe
1Indesign
Jun 17, 2026
Feb 11, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitiga...Show more
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
-
-
Jun 17, 2026
Feb 11, 2025
6.0 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in...Show more
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function. This could allow an attacker with Medium (MED) or higher privileges to cause the device to enter an insecure cold start state.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Feb 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits,...Show more
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.Show less
1Checkpoint
1Gaia Os
Jun 17, 2026
Feb 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur...Show more
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Feb 6, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
1Huawei
1Harmonyos
Jun 17, 2026
Feb 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.
1F5
1Big Ip Policy Enforcement Manager
Jun 17, 2026
Feb 5, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
1Samsung
1Blockchain Keystore
Jun 17, 2026
Feb 4, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vul...Show more
Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Feb 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
1Qualcomm
185Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+182 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption during management frame processing due to mismatch in T2LM info element.
1Qualcomm
165Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+162 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while parsing the OCI IE with invalid length.
1Qualcomm
56Ar8035 Firmware
C V2x 9150 FirmwareFastconnect 6900 Firmware+53 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure while processing IO control commands.
1Qualcomm
71Ar8035 Firmware
C V2x 9150 FirmwareFastconnect 6800 Firmware+68 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure during audio playback.
1Qualcomm
28Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQam8295p Firmware+25 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure while processing information on firmware image during core initialization.
1Qualcomm
40Ar8035 Firmware
Fastconnect 7800 FirmwareQca6584au Firmware+37 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
1Google
1Android
Jun 17, 2026
Feb 3, 2025
N/A· v4
3.9 LOW· v3
N/A· v2
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained th...Show more
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.Show less