CWE-125
9,090 CVEs • Abstraction: Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CVEs (9,090)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining bu...Show more |
1Opencryptoki Project 1Opencryptoki Jun 17, 2026 Apr 16, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length param...Show more |
ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. |
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium) |
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security...Show more |
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentiall...Show more |
Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could...Show more |
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where...Show more |
InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leve...Show more |
Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could l...Show more |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJul 24, 2026 Apr 14, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 7Windows 11 23h2 Windows 11 24h2Windows 11 25h2+4 moreJul 24, 2026 Apr 14, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
1Microsoft 5365 Apps ExcelOffice+2 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
1Microsoft 6Windows 11 23h2 Windows 11 24h2Windows 11 25h2+3 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. |
1Microsoft 9Windows 10 21h2 Windows 10 22h2Windows 11 23h2+6 moreJun 17, 2026 Apr 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Apr 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. |
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker...Show more |
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged pr...Show more |