CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,413)
page 294 of 471| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20921 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20920 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20919 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20918 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20917 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20916 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20915 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20914 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-20913 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | ||
| CVE-2025-21098 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check. | ||
| CVE-2025-20042 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read. | ||
| CVE-2024-43056 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | ||
| CVE-2025-20648 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584. | ||
| CVE-2025-21124 | Med | 0.36 | 5.5 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires… | ||
| CVE-2025-24149 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to disclosure of user… | ||
| CVE-2025-24092 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2025 | This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information. | ||
| CVE-2024-54507 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2025 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory. | ||
| CVE-2025-21374 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows CSC Service Information Disclosure Vulnerability | ||
| CVE-2025-21257 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | ||
| CVE-2024-45070 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.
- risk 0.36cvss 5.5epss 0.00
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
- risk 0.36cvss 5.5epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…
- risk 0.36cvss 5.5epss 0.00
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to disclosure of user…
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.
- risk 0.36cvss 5.5epss 0.01
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.
- risk 0.36cvss 5.5epss 0.01
Windows CSC Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.