CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,337)
page 435 of 467| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62351 | Hig | 0.00 | 7.5 | 0.00 | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte… | ||
| CVE-2026-15030 | Med | 0.00 | — | 0.00 | Jul 15, 2026 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to… | ||
| CVE-2026-47979 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2026-15720 | Hig | 0.00 | 8.6 | 0.00 | Jul 14, 2026 | In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service. | ||
| CVE-2026-58539 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-58529 | Hig | 0.00 | 7.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-58528 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-57094 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-57085 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | ||
| CVE-2026-56195 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-56192 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-56186 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-56176 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55898 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55139 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55122 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55121 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55058 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55054 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-55050 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
- risk 0.00cvss 7.5epss 0.00
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte…
- risk 0.00cvss —epss 0.00
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to…
- risk 0.00cvss 5.5epss 0.00
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.00cvss 8.6epss 0.00
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
- risk 0.00cvss 6.5epss 0.01
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 6.8epss 0.00
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.00cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 8.1epss 0.01
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.1epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.