CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,427)
page 284 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62786 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62743 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62738 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62703 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61933 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59128 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-11743 | Med | 0.36 | 6.6 | 0.00 | Aug 7, 2026 | The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because offset is a signed off_t while size is unsigned, a negative offset is converted… | ||
| CVE-2026-66151 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2026 | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash. | ||
| CVE-2026-7405 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service | ||
| CVE-2026-68743 | Med | 0.36 | 5.5 | 0.00 | Aug 4, 2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket,… | ||
| CVE-2026-68742 | Med | 0.36 | 5.5 | 0.00 | Aug 3, 2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an… | ||
| CVE-2026-20494 | Med | 0.36 | 5.5 | 0.00 | Aug 3, 2026 | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314,… | ||
| CVE-2026-17550 | Med | 0.36 | 5.5 | 0.00 | Jul 29, 2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | ||
| CVE-2026-43738 | Med | 0.36 | 5.5 | 0.00 | Jul 27, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory. | ||
| CVE-2026-15003 | Med | 0.36 | 5.6 | 0.00 | Jul 27, 2026 | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by… | ||
| CVE-2026-47979 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2026 | Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2026-49177 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | ||
| CVE-2026-47969 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2026 | Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2020-9713 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2026 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this… | ||
| CVE-2020-9711 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2026 | Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive… |
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 6.6epss 0.00
The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because offset is a signed off_t while size is unsigned, a negative offset is converted…
- risk 0.36cvss 5.5epss 0.00
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
- risk 0.36cvss 5.5epss 0.00
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
- risk 0.36cvss 5.5epss 0.00
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket,…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an…
- risk 0.36cvss 5.5epss 0.00
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314,…
- risk 0.36cvss 5.5epss 0.00
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
- risk 0.36cvss 5.6epss 0.00
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by…
- risk 0.36cvss 5.5epss 0.00
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.36cvss 5.5epss 0.00
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this…
- risk 0.36cvss 5.5epss 0.00
Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive…