CWE-125
9,090 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,090)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd()...Show more |
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of t...Show more |
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in component...Show more |
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 byt...Show more |
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to discl...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to discl...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to discl...Show more |
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitiv...Show more |
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). I...Show more |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packe...Show more |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 23h2+5 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
1Microsoft 15Remote Desktop Client Windows 10 1607Windows 10 1809+12 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreJun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. |
1Microsoft 7365 Apps Microsoft 365Office 2016+4 moreJun 19, 2026 Jun 9, 2026 N/A· v4 3.3 LOW· v3 N/A· v2 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
1Microsoft 4365 Apps Microsoft 365Office 2021+1 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. |