CWE-125
9,136 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,136)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory. |
Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory. |
Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory. |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Aug 6, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 11...Show more |
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not requir...Show more |
1Qualcomm 164Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+161 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. |
1Qualcomm 167Csr8811 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+164 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
1Qualcomm 96Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6800 Firmware+93 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TID-to-link mapping IE elements. |
1Qualcomm 148Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+145 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping action frame. |
1Qualcomm 150Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+147 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. |
1Qualcomm 192Ar8035 Firmware Csr8811 FirmwareFastconnect 6200 Firmware+189 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 169Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+166 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 247205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
1Qualcomm 94Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6800 Firmware+91 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS during music playback of ALAC content. |
1Qualcomm 129Csr8811 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+126 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Information disclosure while handling beacon probe frame during scan entry generation in client side. |
1Qualcomm 175Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+172 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Information disclosure while handling beacon or probe response frame in STA. |
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitiga...Show more |