Out-of-bounds Read (CWE-125)
CWE-125 is a Base weakness in which a product reads data past the end, or before the beginning, of the intended buffer. It often comes from incorrect length or offset calculations, or from relying on a sentinel such as a NUL character that is missing.
About CWE-125
Attackers may read secrets such as cryptographic keys, personal data or memory addresses. Leaked addresses can help defeat ASLR for another flaw, and invalid reads may crash the process.
Mitigations
- +Validate and correctly calculate every length argument, buffer size and offset.
- +Do not rely on sentinel characters in untrusted input to stop a read.
- +Use an accept-known-good input validation strategy.
- +Use a language that provides appropriate memory abstractions.
Detection
Fuzzing and automated static analysis are rated highly effective, and runtime checkers like AddressSanitizer help during testing.
CWE-125 Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2023-36424 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 12.2% | KEV | 2023-11-14 |
| CVE-2026-3055 | Insufficient input validation leading to memory overread | NetScaler | 9.3 | 4.0% | KEV | 2026-03-23 |
| CVE-2025-5777 | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread | NetScaler | 9.3 | 100.0% | KEV | 2025-06-17 |
| CVE-2025-24991 | Windows NTFS Information Disclosure Vulnerability | Microsoft | 5.5 | 2.0% | KEV | 2025-03-11 |
| CVE-2021-25487 | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | Samsung Mobile | 7.3 | 0.6% | KEV | 2021-10-06 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-125?→
CWE-125 is an out-of-bounds read: the product reads memory outside the buffer it intended to read.
Why does an out-of-bounds read matter if nothing is written?→
MITRE notes it can expose secrets and memory addresses. Those addresses can help bypass ASLR when exploiting a separate weakness.
How many exploited vulnerabilities are classified as CWE-125?→
This database lists 5 CVE records mapped to CWE-125 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2023-36424, CVE-2026-3055, CVE-2025-5777.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.