CWE-125 · 9,091 records
Out-of-bounds Read
CVEs in this class
9,112 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2025-5777Weaponized | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Critical9.3 | KEV | 100.0% | Jun 17, 2025 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
79This week | CVE-2016-1646Weaponized | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consgoogle · chrome · CWE-125 | High8.8 | KEV | 48.1% | Mar 29, 2016 |
77This week | CVE-2017-5030Weaponized | Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Androidgoogle · chrome · CWE-125 | High8.8 | KEV | 40.6% | Apr 24, 2017 |
69This week | CVE-2016-4523Weaponized | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (trihedral · vtscada · CWE-125 | High7.5 | KEV | 31.2% | Jun 9, 2016 |
68This week | CVE-2026-3055Weaponized | Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Critical9.3 | KEV | 4.0% | Mar 23, 2026 |
67This week | CVE-2025-5419Weaponized | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-125 | High8.8 | KEV | 7.8% | Jun 2, 2025 |
66This week | CVE-2020-8794Weaponized | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.opensmtpd · opensmtpd · CWE-125 | Critical9.8 | — | 88.9% | Feb 25, 2020 |
66This week | CVE-2026-11645Weaponized | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sangoogle · chrome · CWE-125 | High8.8 | KEV | 2.2% | Jun 8, 2026 |
65This week | CVE-2023-36424Weaponized | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-125 | High7.8 | KEV | 12.2% | Nov 14, 2023 |
64This week | CVE-2021-25216No exploit | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackdebian · debian linux · CWE-125 | Critical9.8 | — | 82.4% | Apr 28, 2021 |
61This week | CVE-2023-42916Weaponized | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Medium6.5 | KEV | 17.8% | Nov 30, 2023 |
61This week | CVE-2021-25487Weaponized | Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it ressamsung · android · CWE-125 | High7.8 | KEV | 0.6% | Oct 6, 2021 |
60This week | CVE-2023-28204Weaponized | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Medium6.5 | KEV | 14.3% | Jun 23, 2023 |
58Plan | CVE-2024-53150Weaponized | ALSA: usb-audio: Fix out of bounds reads when finding clock sourceslinux · linux kernel · CWE-125 | High7.1 | KEV | 1.4% | Dec 24, 2024 |
57Plan | CVE-2023-21769No exploit | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-125 | High7.5 | — | 88.7% | Apr 11, 2023 |
57Plan | CVE-2021-44142Proof of concept | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interosamba · samba · CWE-125 | High8.8 | — | 73.4% | Feb 21, 2022 |
57Plan | CVE-2020-11899Weaponized | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.4 | KEV | 18.6% | Jun 17, 2020 |
56Plan | CVE-2019-6443Proof of concept | An issue was discovered in NTPsec before 1.1.3.ntpsec · ntpsec · CWE-125 | Critical9.1 | — | 66.9% | Jan 16, 2019 |
55Plan | CVE-2024-49113Proof of concept | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerabilitymicrosoft · windows 10 1507 · CWE-125 | High7.5 | — | 83.6% | Dec 11, 2024 |
55Plan | CVE-2020-25109No exploit | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Critical9.8 | — | 53.7% | Dec 11, 2020 |
55Plan | CVE-2020-25110No exploit | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Critical9.8 | — | 53.7% | Dec 11, 2020 |
55Plan | CVE-2020-25107No exploit | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.ethernut · nut\/os · CWE-125 | Critical9.8 | — | 53.7% | Dec 11, 2020 |
55Plan | CVE-2025-22226Weaponized | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS.vmware · esxi · CWE-125 | Medium6.0 | KEV | 1.8% | Mar 4, 2025 |
53Plan | CVE-2019-8457No exploit | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tsqlite · sqlite · CWE-125 | Critical9.8 | — | 45.4% | May 30, 2019 |
- CVE-2025-577797Now
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
CriticalCVSS 9.3KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerJun 17, 2025
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2016-164679This week
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly cons
HighCVSS 8.8KEVWeaponizedEPSS 48%google · chromeMar 29, 2016
- CVE-2017-503077This week
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android
HighCVSS 8.8KEVWeaponizedEPSS 41%google · chromeApr 24, 2017
- CVE-2016-452369This week
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (
HighCVSS 7.5KEVWeaponizedEPSS 31%trihedral · vtscadaJun 9, 2016
- CVE-2026-305568This week
Insufficient input validation leading to memory overread
CriticalCVSS 9.3KEVWeaponizedEPSS 4%citrix · netscaler application delivery controllerMar 23, 2026
- CVE-2025-541967This week
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption
HighCVSS 8.8KEVWeaponizedEPSS 8%google · chromeJun 2, 2025
- CVE-2020-879466This week
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.
CriticalCVSS 9.8WeaponizedEPSS 89%opensmtpd · opensmtpdFeb 25, 2020
- CVE-2026-1164566This week
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a san
HighCVSS 8.8KEVWeaponizedEPSS 2%google · chromeJun 8, 2026
- CVE-2023-3642465This week
Windows Common Log File System Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 12%microsoft · windows 10 1507Nov 14, 2023
- CVE-2021-2521664This week
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
CriticalCVSS 9.8No exploitEPSS 82%debian · debian linuxApr 28, 2021
- CVE-2023-4291661This week
An out-of-bounds read was addressed with improved input validation.
MediumCVSS 6.5KEVWeaponizedEPSS 18%apple · safariNov 30, 2023
- CVE-2021-2548761This week
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it res
HighCVSS 7.8KEVWeaponizedEPSS 1%samsung · androidOct 6, 2021
- CVE-2023-2820460This week
An out-of-bounds read was addressed with improved input validation.
MediumCVSS 6.5KEVWeaponizedEPSS 14%apple · safariJun 23, 2023
- CVE-2024-5315058Plan
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
HighCVSS 7.1KEVWeaponizedEPSS 1%linux · linux kernelDec 24, 2024
- CVE-2023-2176957Plan
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 89%microsoft · windows 10 1607Apr 11, 2023
- CVE-2021-4414257Plan
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero
HighCVSS 8.8Proof of conceptEPSS 73%samba · sambaFeb 21, 2022
- CVE-2020-1189957Plan
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
MediumCVSS 5.4KEVWeaponizedEPSS 19%treck · tcp\/ipJun 17, 2020
- CVE-2019-644356Plan
An issue was discovered in NTPsec before 1.1.3.
CriticalCVSS 9.1Proof of conceptEPSS 67%ntpsec · ntpsecJan 16, 2019
- CVE-2024-4911355Plan
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
HighCVSS 7.5Proof of conceptEPSS 84%microsoft · windows 10 1507Dec 11, 2024
- CVE-2020-2510955Plan
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
CriticalCVSS 9.8No exploitEPSS 54%ethernut · nut\/osDec 11, 2020
- CVE-2020-2511055Plan
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
CriticalCVSS 9.8No exploitEPSS 54%ethernut · nut\/osDec 11, 2020
- CVE-2020-2510755Plan
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1.
CriticalCVSS 9.8No exploitEPSS 54%ethernut · nut\/osDec 11, 2020
- CVE-2025-2222655Plan
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS.
MediumCVSS 6.0KEVWeaponizedEPSS 2%vmware · esxiMar 4, 2025
- CVE-2019-845753Plan
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t
CriticalCVSS 9.8No exploitEPSS 45%sqlite · sqliteMay 30, 2019