← Back
CWE-125

9,136 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,136)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Notes
Jun 17, 2026
Aug 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
1Samsung
1Notes
Jun 17, 2026
Aug 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
1Samsung
1Notes
Jun 17, 2026
Aug 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 11...Show more
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.Show less
1Ofono Project
1Ofono
Jun 17, 2026
Aug 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not requir...Show more
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SMS message lists. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23157.Show less
1Qualcomm
164Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+161 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
1Qualcomm
167Csr8811 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+164 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
1Qualcomm
96Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6800 Firmware+93 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing TID-to-link mapping IE elements.
1Qualcomm
148Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+145 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the received TID-to-link mapping action frame.
1Qualcomm
150Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+147 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
1Qualcomm
192Ar8035 Firmware
Csr8811 FirmwareFastconnect 6200 Firmware+189 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
1Qualcomm
319315 5g Iot Modem Firmware
860 Mobile Platform FirmwareApq8064au Firmware+316 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing ESP IE from beacon/probe response frame.
1Qualcomm
169Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+166 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
1Qualcomm
247Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
1Qualcomm
247Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
1Qualcomm
247205 Mobile Platform Firmware
215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
1Qualcomm
94Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6800 Firmware+91 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS during music playback of ALAC content.
1Qualcomm
129Csr8811 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+126 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while handling beacon probe frame during scan entry generation in client side.
1Qualcomm
175Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+172 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while handling beacon or probe response frame in STA.
1Adobe
1Indesign
Jun 17, 2026
Aug 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitiga...Show more
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less