← Back
CWE-125

9,162 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,162)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
61Aqt1000 Firmware
Flight Rb5 5g Platform FirmwareQca6390 Firmware+58 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
1Qualcomm
115Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+112 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing WLAN beacon or probe-response frame.
1Qualcomm
79Csr8811 Firmware
Immersive Home 214 Platform FirmwareImmersive Home 216 Platform Firmware+76 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while parsing FT Information Elements.
1Qualcomm
270315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+267 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while processing frames with missing header fields.
1Qualcomm
151Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+148 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jun 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jun 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to rela...Show more
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.Show less
2Opensc Project
Redhat
2Enterprise Linux
Opensc
Jun 17, 2026
Jun 1, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_hav...Show more
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.Show less
3Debian
LinuxSuse
3Debian Linux
Linux EnterpriseLinux Kernel
Jun 17, 2026
May 31, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this...Show more
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.Show less
2Linux
Netapp
6H300s
H410cH410s+3 more
Jun 17, 2026
May 31, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
1Huawei
1Harmonyos
Jun 17, 2026
May 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
1Garmin
1Connect Iq
Jun 17, 2026
May 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that...Show more
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.Show less
1Gpac
1Gpac
Jun 17, 2026
May 22, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
1Eclipse
1Openj9
Jun 17, 2026
May 22, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.
1Qt
1Qt
Jun 17, 2026
May 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is...Show more
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004Show less
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction...Show more
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252763983Show less
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...Show more
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629583; Issue ID: ALPS07629583.Show less
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...Show more
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07581668; Issue ID: ALPS07581668.Show less
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...Show more
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.Show less