← Back
CWE-125

9,172 CVEs • Abstraction: Base

Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (9,172)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
May 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges...Show more
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213519176Show less
3Apple
FedoraprojectVim
3Fedora
MacosVim
Jun 17, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
3Apple
DebianRuby Lang
3Debian Linux
MacosRuby
Jun 17, 2026
May 9, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.
2Admesh Project
Debian
2Admesh
Debian Linux
Nov 21, 2024
May 8, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
1Adobe
1Photoshop
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory str...Show more
Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Photoshop
Jun 17, 2026
May 6, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t...Show more
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...Show more
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.Show less
1Sound Exchange Project
1Sound Exchange
Jun 17, 2026
May 2, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
1Deltaww
1Asda Soft
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.
1Libmobi Project
1Libmobi
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensi...Show more
Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.Show less
1Libmobi Project
1Libmobi
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.
2Debian
Gpac
2Debian Linux
Gpac
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it alloc...Show more
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.Show less
1Radare
1Radare2
Jun 17, 2026
Apr 24, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can a...Show more
Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).Show less
1Radare
1Radare2
Jun 17, 2026
Apr 24, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allo...Show more
Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).Show less
1Mruby
1Mruby
Jun 17, 2026
Apr 23, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
2Fedoraproject
Freetype
2Fedora
Freetype
Jul 9, 2026
Apr 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.