← Back
CWE-125

9,140 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,140)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
FedoraprojectLinux+1 more
4Enterprise Linux
FedoraLinux Kernel+1 more
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.Show less
1Gpac
1Gpac
Jun 17, 2026
Jan 8, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
1Paddlepaddle
1Paddlepaddle
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
1Wireshark
1Wireshark
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
1Cesanta
1Mjs
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.
1Silabs
1Gecko Software Development Kit
Jun 17, 2026
Jan 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
1Qualcomm
1Qcn7606 Firmware
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.
1Qualcomm
102Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+99 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
1Gnu
1Libredwg
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...Show more
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.Show less
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...Show more
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.Show less
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...Show more
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.Show less
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...Show more
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.Show less
1Hongliuliao
1Ehttp
Jun 17, 2026
Dec 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
1Hihonor
1Magic Ui
Jun 17, 2026
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.
1Hihonor
1Magic Ui
Jun 17, 2026
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.
1Cybergarage
1Mupnp For C
Jun 17, 2026
Dec 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
mupnp/net/uri.c in mUPnP for C through 3.0.2 has an out-of-bounds read and application crash because it lacks a certain host length recalculation.
1Proftpd
1Proftpd
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
1Panasonic
1Fpwin Pro
Jun 17, 2026
Dec 19, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bouds read vulnerability in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.
1Silabs
1Gecko Software Development Kit
Jun 17, 2026
Dec 15, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from...Show more
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.Show less