CWE-125 · 9.091 kayıt
Out-of-bounds Read
Bu sınıftaki CVE’ler
9.112 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2025-5777Silahlaştırılmış | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Kritik9,3 | KEV | %100,0 | 17 Haz 2025 |
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
79Bu hafta | CVE-2016-1646Silahlaştırılmış | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consgoogle · chrome · CWE-125 | Yüksek8,8 | KEV | %48,1 | 29 Mar 2016 |
77Bu hafta | CVE-2017-5030Silahlaştırılmış | Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Androidgoogle · chrome · CWE-125 | Yüksek8,8 | KEV | %40,6 | 24 Nis 2017 |
69Bu hafta | CVE-2016-4523Silahlaştırılmış | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (trihedral · vtscada · CWE-125 | Yüksek7,5 | KEV | %31,2 | 9 Haz 2016 |
68Bu hafta | CVE-2026-3055Silahlaştırılmış | Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Kritik9,3 | KEV | %4,0 | 23 Mar 2026 |
67Bu hafta | CVE-2025-5419Silahlaştırılmış | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-125 | Yüksek8,8 | KEV | %7,8 | 2 Haz 2025 |
66Bu hafta | CVE-2020-8794Silahlaştırılmış | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.opensmtpd · opensmtpd · CWE-125 | Kritik9,8 | — | %88,9 | 25 Şub 2020 |
66Bu hafta | CVE-2026-11645Silahlaştırılmış | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sangoogle · chrome · CWE-125 | Yüksek8,8 | KEV | %2,2 | 8 Haz 2026 |
65Bu hafta | CVE-2023-36424Silahlaştırılmış | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-125 | Yüksek7,8 | KEV | %12,2 | 14 Kas 2023 |
64Bu hafta | CVE-2021-25216İstismar yok | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackdebian · debian linux · CWE-125 | Kritik9,8 | — | %82,4 | 28 Nis 2021 |
61Bu hafta | CVE-2023-42916Silahlaştırılmış | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Orta6,5 | KEV | %17,8 | 30 Kas 2023 |
61Bu hafta | CVE-2021-25487Silahlaştırılmış | Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it ressamsung · android · CWE-125 | Yüksek7,8 | KEV | %0,6 | 6 Eki 2021 |
60Bu hafta | CVE-2023-28204Silahlaştırılmış | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Orta6,5 | KEV | %14,3 | 23 Haz 2023 |
58Planlayın | CVE-2024-53150Silahlaştırılmış | ALSA: usb-audio: Fix out of bounds reads when finding clock sourceslinux · linux kernel · CWE-125 | Yüksek7,1 | KEV | %1,4 | 24 Ara 2024 |
57Planlayın | CVE-2023-21769İstismar yok | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-125 | Yüksek7,5 | — | %88,7 | 11 Nis 2023 |
57Planlayın | CVE-2021-44142Kavram kanıtı | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interosamba · samba · CWE-125 | Yüksek8,8 | — | %73,4 | 21 Şub 2022 |
57Planlayın | CVE-2020-11899Silahlaştırılmış | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Orta5,4 | KEV | %18,6 | 17 Haz 2020 |
56Planlayın | CVE-2019-6443Kavram kanıtı | An issue was discovered in NTPsec before 1.1.3.ntpsec · ntpsec · CWE-125 | Kritik9,1 | — | %66,9 | 16 Oca 2019 |
55Planlayın | CVE-2024-49113Kavram kanıtı | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerabilitymicrosoft · windows 10 1507 · CWE-125 | Yüksek7,5 | — | %83,6 | 11 Ara 2024 |
55Planlayın | CVE-2020-25109İstismar yok | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Kritik9,8 | — | %53,7 | 11 Ara 2020 |
55Planlayın | CVE-2020-25110İstismar yok | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Kritik9,8 | — | %53,7 | 11 Ara 2020 |
55Planlayın | CVE-2020-25107İstismar yok | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Kritik9,8 | — | %53,7 | 11 Ara 2020 |
55Planlayın | CVE-2025-22226Silahlaştırılmış | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS.vmware · esxi · CWE-125 | Orta6,0 | KEV | %1,8 | 4 Mar 2025 |
53Planlayın | CVE-2019-8457İstismar yok | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tsqlite · sqlite · CWE-125 | Kritik9,8 | — | %45,4 | 30 May 2019 |
- CVE-2025-577797Hemen
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %100citrix · netscaler application delivery controller17 Haz 2025
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2016-164679Bu hafta
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly cons
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %48google · chrome29 Mar 2016
- CVE-2017-503077Bu hafta
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41google · chrome24 Nis 2017
- CVE-2016-452369Bu hafta
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %31trihedral · vtscada9 Haz 2016
- CVE-2026-305568Bu hafta
Insufficient input validation leading to memory overread
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %4citrix · netscaler application delivery controller23 Mar 2026
- CVE-2025-541967Bu hafta
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %8google · chrome2 Haz 2025
- CVE-2020-879466Bu hafta
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.
KritikCVSS 9,8SilahlaştırılmışEPSS %89opensmtpd · opensmtpd25 Şub 2020
- CVE-2026-1164566Bu hafta
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a san
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %2google · chrome8 Haz 2026
- CVE-2023-3642465Bu hafta
Windows Common Log File System Driver Elevation of Privilege Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %12microsoft · windows 10 150714 Kas 2023
- CVE-2021-2521664Bu hafta
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
KritikCVSS 9,8İstismar yokEPSS %82debian · debian linux28 Nis 2021
- CVE-2023-4291661Bu hafta
An out-of-bounds read was addressed with improved input validation.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %18apple · safari30 Kas 2023
- CVE-2021-2548761Bu hafta
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it res
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1samsung · android6 Eki 2021
- CVE-2023-2820460Bu hafta
An out-of-bounds read was addressed with improved input validation.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %14apple · safari23 Haz 2023
- CVE-2024-5315058Planlayın
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
YüksekCVSS 7,1KEVSilahlaştırılmışEPSS %1linux · linux kernel24 Ara 2024
- CVE-2023-2176957Planlayın
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %89microsoft · windows 10 160711 Nis 2023
- CVE-2021-4414257Planlayın
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero
YüksekCVSS 8,8Kavram kanıtıEPSS %73samba · samba21 Şub 2022
- CVE-2020-1189957Planlayın
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %19treck · tcp\/ip17 Haz 2020
- CVE-2019-644356Planlayın
An issue was discovered in NTPsec before 1.1.3.
KritikCVSS 9,1Kavram kanıtıEPSS %67ntpsec · ntpsec16 Oca 2019
- CVE-2024-4911355Planlayın
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %84microsoft · windows 10 150711 Ara 2024
- CVE-2020-2510955Planlayın
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
KritikCVSS 9,8İstismar yokEPSS %54ethernut · nut\/os11 Ara 2020
- CVE-2020-2511055Planlayın
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
KritikCVSS 9,8İstismar yokEPSS %54ethernut · nut\/os11 Ara 2020
- CVE-2020-2510755Planlayın
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
KritikCVSS 9,8İstismar yokEPSS %54ethernut · nut\/os11 Ara 2020
- CVE-2025-2222655Planlayın
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS.
OrtaCVSS 6,0KEVSilahlaştırılmışEPSS %2vmware · esxi4 Mar 2025
- CVE-2019-845753Planlayın
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t
KritikCVSS 9,8İstismar yokEPSS %45sqlite · sqlite30 May 2019