← Back
CWE-125

9,090 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Media Encoder
Jul 17, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this is...Show more
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not a...Show more
An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata.Show less
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Addit...Show more
A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.Show less
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Windows 11 26h1
Jul 16, 2026
Jul 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 20, 2026
Jul 14, 2026
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
1Microsoft
6365 Apps
Microsoft 365Office 2016+3 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
1Microsoft
7365 Apps
Microsoft 365Office 2016+4 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
1Microsoft
7365 Apps
ExcelMicrosoft 365+4 more
Jul 15, 2026
Jul 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
1Microsoft
6365 Apps
Microsoft 365Office 2016+3 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
1Microsoft
7365 Apps
ExcelMicrosoft 365+4 more
Jul 15, 2026
Jul 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
1Microsoft
7365 Apps
Microsoft 365Office 2016+4 more
Jul 15, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
1Microsoft
7365 Apps
ExcelMicrosoft 365+4 more
Jul 15, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
1Microsoft
7365 Apps
ExcelOffice+4 more
Jul 15, 2026
Jul 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
1Microsoft
8365 Apps
Microsoft 365Office 2019+5 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.