CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 220 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-79112 | Med | 0.42 | 6.5 | 0.00 | Aug 25, 2026 | Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-75370 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message. | ||
| CVE-2026-77237 | Med | 0.42 | 6.5 | 0.00 | Aug 21, 2026 | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or… | ||
| CVE-2026-54789 | Hig | 0.42 | 7.5 | 0.00 | Aug 21, 2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie… | ||
| CVE-2026-53587 | Hig | 0.42 | 7.5 | 0.00 | Aug 20, 2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in… | ||
| CVE-2026-76641 | Hig | 0.42 | 7.5 | 0.00 | Aug 20, 2026 | Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to… | ||
| CVE-2026-69550 | Med | 0.42 | 6.5 | 0.01 | Aug 19, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-17028 | Med | 0.42 | 6.5 | 0.00 | Aug 19, 2026 | IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition… | ||
| CVE-2026-16853 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | ||
| CVE-2026-70328 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-70327 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62814 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62782 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62745 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62742 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62720 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62718 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62716 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62715 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62714 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
- risk 0.42cvss 6.5epss 0.00
Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- risk 0.42cvss 6.5epss 0.00
An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.
- risk 0.42cvss 6.5epss 0.00
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or…
- risk 0.42cvss 7.5epss 0.00
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie…
- risk 0.42cvss 7.5epss 0.00
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in…
- risk 0.42cvss 7.5epss 0.00
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to…
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition…
- risk 0.42cvss 6.5epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.