CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,795)
page 474 of 490| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56193 | Hig | 0.00 | 7.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-54996 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54991 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54988 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-54111 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50300 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-49794 | Med | 0.00 | 4.6 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-53566 | Med | 0.00 | — | 0.00 | Jul 14, 2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. | ||
| CVE-2026-40454 | Hig | 0.00 | 7.5 | 0.00 | Jul 10, 2026 | Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5… | ||
| CVE-2026-58307 | Med | 0.00 | 6.1 | 0.00 | Jul 9, 2026 | Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c. | ||
| CVE-2026-58304 | Med | 0.00 | 6.1 | 0.00 | Jul 9, 2026 | Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a. | ||
| CVE-2026-57258 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes. | ||
| CVE-2026-57257 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes. | ||
| CVE-2026-57255 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing… | ||
| CVE-2026-57253 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing. | ||
| CVE-2026-57243 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash. | ||
| CVE-2026-57241 | Med | 0.00 | 6.1 | 0.00 | Jul 8, 2026 | The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due… | ||
| CVE-2026-14422 | Hig | 0.00 | 8.8 | 0.00 | Jul 1, 2026 | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14420 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14416 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 4.6epss 0.00
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.00cvss —epss 0.00
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
- risk 0.00cvss 7.5epss 0.00
Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5…
- risk 0.00cvss 6.1epss 0.00
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
- risk 0.00cvss 6.1epss 0.00
Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.
- risk 0.00cvss 6.1epss 0.00
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
- risk 0.00cvss 6.1epss 0.00
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
- risk 0.00cvss 6.1epss 0.00
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing…
- risk 0.00cvss 6.1epss 0.00
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.
- risk 0.00cvss 6.1epss 0.00
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
- risk 0.00cvss 6.1epss 0.00
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due…
- risk 0.00cvss 8.8epss 0.00
Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 9.6epss 0.00
Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 9.6epss 0.00
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)