Skip to content
Noroxi

CWE-125 · 9,091 records

Out-of-bounds Read

CVEs in this class

9,112 records

  • NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread

    CriticalCVSS 9.3KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerJun 17, 2025

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • CVE-2016-1646
    79This week

    The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly cons

    HighCVSS 8.8KEVWeaponizedEPSS 48%

    google · chromeMar 29, 2016

  • CVE-2017-5030
    77This week

    Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android

    HighCVSS 8.8KEVWeaponizedEPSS 41%

    google · chromeApr 24, 2017

  • CVE-2016-4523
    69This week

    The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (

    HighCVSS 7.5KEVWeaponizedEPSS 31%

    trihedral · vtscadaJun 9, 2016

  • CVE-2026-3055
    68This week

    Insufficient input validation leading to memory overread

    CriticalCVSS 9.3KEVWeaponizedEPSS 4%

    citrix · netscaler application delivery controllerMar 23, 2026

  • CVE-2025-5419
    67This week

    Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption

    HighCVSS 8.8KEVWeaponizedEPSS 8%

    google · chromeJun 2, 2025

  • CVE-2020-8794
    66This week

    OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.

    CriticalCVSS 9.8WeaponizedEPSS 89%

    opensmtpd · opensmtpdFeb 25, 2020

  • CVE-2026-11645
    66This week

    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a san

    HighCVSS 8.8KEVWeaponizedEPSS 2%

    google · chromeJun 8, 2026

  • CVE-2023-36424
    65This week

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 12%

    microsoft · windows 10 1507Nov 14, 2023

  • CVE-2021-25216
    64This week

    A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack

    CriticalCVSS 9.8No exploitEPSS 82%

    debian · debian linuxApr 28, 2021

  • CVE-2023-42916
    61This week

    An out-of-bounds read was addressed with improved input validation.

    MediumCVSS 6.5KEVWeaponizedEPSS 18%

    apple · safariNov 30, 2023

  • CVE-2021-25487
    61This week

    Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it res

    HighCVSS 7.8KEVWeaponizedEPSS 1%

    samsung · androidOct 6, 2021

  • CVE-2023-28204
    60This week

    An out-of-bounds read was addressed with improved input validation.

    MediumCVSS 6.5KEVWeaponizedEPSS 14%

    apple · safariJun 23, 2023

  • ALSA: usb-audio: Fix out of bounds reads when finding clock sources

    HighCVSS 7.1KEVWeaponizedEPSS 1%

    linux · linux kernelDec 24, 2024

  • Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 89%

    microsoft · windows 10 1607Apr 11, 2023

  • The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero

    HighCVSS 8.8Proof of conceptEPSS 73%

    samba · sambaFeb 21, 2022

  • The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

    MediumCVSS 5.4KEVWeaponizedEPSS 19%

    treck · tcp\/ipJun 17, 2020

  • An issue was discovered in NTPsec before 1.1.3.

    CriticalCVSS 9.1Proof of conceptEPSS 67%

    ntpsec · ntpsecJan 16, 2019

  • Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

    HighCVSS 7.5Proof of conceptEPSS 84%

    microsoft · windows 10 1507Dec 11, 2024

  • An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.

    CriticalCVSS 9.8No exploitEPSS 54%

    ethernut · nut\/osDec 11, 2020

  • An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.

    CriticalCVSS 9.8No exploitEPSS 54%

    ethernut · nut\/osDec 11, 2020

  • An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.

    CriticalCVSS 9.8No exploitEPSS 54%

    ethernut · nut\/osDec 11, 2020

  • VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS.

    MediumCVSS 6.0KEVWeaponizedEPSS 2%

    vmware · esxiMar 4, 2025

  • SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t

    CriticalCVSS 9.8No exploitEPSS 45%

    sqlite · sqliteMay 30, 2019

All vulnerability classes