CWE-125
9,171 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,171)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to...Show more |
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi...Show more |
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to...Show more |
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi...Show more |
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi...Show more |
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access. |
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Media Software Development Kit Jun 17, 2026 Feb 16, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Iris Xe Max Dedicated Graphics Jun 17, 2026 Feb 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged user to potentially enable information disclosure via local access. |
Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access. |
1Microsoft 7Windows 10 1809 Windows 10 20h2Windows 10 21h2+4 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Secure Channel Denial of Service Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft ODBC Driver Remote Code Execution Vulnerability |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Feb 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Microsoft Office Information Disclosure Vulnerability |
1Microsoft 13Windows 10 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows iSCSI Service Denial of Service Vulnerability |
1Microsoft 10Windows 10 Windows 10 1607Windows 10 1809+7 moreJun 17, 2026 Feb 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability |
1Microsoft 13Windows 10 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability |
1Microsoft 3Windows 11 21h2 Windows 11 22h2Windows Server 2022Jun 17, 2026 Feb 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 HTTP.sys Information Disclosure Vulnerability |
GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the `av_pair` is not checked pro...Show more |
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit intege...Show more |