CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
3,892 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-5777 — NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
- CVE-2026-3055 — Insufficient input validation leading to memory overread
- CVE-2026-14090 — Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed
- CVE-2026-78989 — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential
- CVE-2026-17701 — Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote atta
- CVE-2026-14416 — Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sa
- CVE-2026-11061 — Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandb
- CVE-2026-24826 — Out-of-bounds write in turso3d
- CVE-2024-5991 — Buffer overread in domain name matching
- CVE-2024-47039 — OOB Read in the android.hardware.boot.IBootControl/default service
- CVE-2024-22004 — Unchecked length in Trusted Application on Google Nest Wifi Pro, leading to out of bounds read
- CVE-2026-82072 — Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins
- CVE-2026-78978 — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential
- CVE-2026-87440 — Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code
- CVE-2026-7995 — Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary co
- CVE-2026-17678 — Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re
- CVE-2026-11301 — Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti
- CVE-2026-11279 — Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co
- CVE-2026-11077 — Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sa
- CVE-2026-33669 — SiYuan has Arbitrary Document Reading within the Publishing Service
Recently published
- CVE-2026-73324 — VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminated RealRTSP Response Line
- CVE-2026-87795 — zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress
- CVE-2026-87736 — An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds
- CVE-2026-81646 — Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
- CVE-2026-49314 — OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability m
- CVE-2026-87602 — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potential
- CVE-2026-87592 — Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory
- CVE-2026-87586 — Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the
- CVE-2026-87640 — Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had co
- CVE-2026-87604 — Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the re
- CVE-2026-87596 — Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the
- CVE-2026-87650 — Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arb
- CVE-2026-87525 — Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read
- CVE-2026-87440 — Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code
- CVE-2026-86564 — Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler
- CVE-2026-18090 — Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block
- CVE-2026-81991 — Acrobat Reader | Out-of-bounds Read (CWE-125)
- CVE-2026-79910 — Acrobat Reader | Out-of-bounds Read (CWE-125)
- CVE-2026-80160 — Acrobat Reader | Out-of-bounds Read (CWE-125)
- CVE-2026-81982 — Acrobat Reader | Out-of-bounds Read (CWE-125)