Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-125 · Out-of-bounds readDefinition on MITRE ↗Clear

17 results

CVE-2026-11645
2026-06-09
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds writeCWE-125 · Out-of-bounds read
Refschromereleases.googleblog.comissues.chromium.orgnvd.nist.gov
Federal remediation due 2026-06-23
CVE-2023-36424
2026-04-13
Microsoft Windows Out-of-Bounds Read Vulnerability
Microsoft

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

CWE-125 · Out-of-bounds read
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-04-27
CVE-2026-3055
2026-03-30
Citrix NetScaler Out-of-Bounds Read Vulnerability
Citrix

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

CWE-125 · Out-of-bounds read
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2026-04-02
CVE-2025-5777
2025-07-10
Citrix NetScaler ADC and Gateway Out-of-Bounds Read VulnerabilityRansomware
Citrix

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

CWE-125 · Out-of-bounds read
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2025-07-11
CVE-2025-5419
2025-06-05
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2025-06-26
CVE-2024-53150
2025-04-09
Linux Kernel Out-of-Bounds Read Vulnerability
Linux

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.

CWE-125 · Out-of-bounds read
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seesource.android.comnvd.nist.gov
Federal remediation due 2025-04-30
CVE-2025-24991
2025-03-11
Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
Microsoft

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

CWE-125 · Out-of-bounds read
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-04-01
CVE-2025-22226
2025-03-04
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
VMware

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

CWE-125 · Out-of-bounds read
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2025-03-25
CVE-2023-42916
2023-12-04
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-125 · Out-of-bounds read
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-12-25
CVE-2021-25487
2023-06-29
Samsung Mobile Devices Out-of-Bounds Read Vulnerability
Samsung

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

CWE-125 · Out-of-bounds read
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2023-07-20
CVE-2023-28204
2023-05-22
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-125 · Out-of-bounds read
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-06-12
CVE-2017-5030
2022-06-08
Google Chromium V8 Memory Corruption Vulnerability
Google

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2016-5198
2022-06-08
Google Chromium V8 Out-of-Bounds Memory Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2014-0160
2022-05-04
OpenSSL Information Disclosure Vulnerability
OpenSSL

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

CWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-05-25
CVE-2022-22675
2022-04-04
Apple macOS Out-of-Bounds Write Vulnerability
Apple

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

CWE-20 · Improper input validationCWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2022-22674
2022-04-04
Apple macOS Out-of-Bounds Read Vulnerability
Apple

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

CWE-20 · Improper input validationCWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2020-11899
2022-03-03
Treck TCP/IP stack Out-of-Bounds Read Vulnerability
Treck TCP/IP stack / IPv6

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

CWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-03-17