What is CWE-125?
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-125 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Memory-Unsafe; Language: C; Language: C++; Technology: ICS/OT.
Source: MITRE CWE (CWE-125 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality — Read Memory. An attacker could get secret values such as cryptographic keys, PII, memory addresses, or other information that could be used in additional attacks.
- Confidentiality — Bypass Protection Mechanism. Out-of-bounds memory could contain memory addresses or other information that can be used to bypass ASLR and other protection mechanisms in order to improve the reliability of exploiting a separate weakness for code execution.
- Availability — DoS: Crash, Exit, or Restart. An attacker could cause a segmentation fault or crash by causing memory to be read outside of the bounds of the buffer. This is especially likely when the code reads a variable amount of data and assumes that a sentinel exists to stop the read operation, such as a NUL in a string.
- Other — Varies by Context. The read operation could produce other undefined or unexpected results.
Source: MITRE CWE, common consequences.
How CWE-125 is exploited in the wild
Threadlinqs maps 69 CVEs to CWE-125, published between 2019-09-11 and 2026-10-04. 6 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 5 critical, 20 high, 31 medium, 9 low. The highest EPSS score in the set is 89.7% (CVE-2026-3055), the modelled probability of exploitation in the next 30 days. 61 tracked threats reference CWE-125 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)” (2026-10-02). Affected products concentrate in MZ Automation GmbH (8), Google (5), Wireshark Foundation (4), among 43 vendors in total.
Vulnerabilities (CVEs)
Showing 40 of 69 CVEs mapped to CWE-125, CISA KEV first, then by CVSS score.
- CVE-2026-3055 — CISA KEV · CVSS 9.3 critical · EPSS 89.7% · published 2026-03-23
- CVE-2021-4034 — CISA KEV · CVSS 7.8 high · EPSS 87.8% · published 2022-01-28
- CVE-2025-5777 — CISA KEV · CVSS 7.5 high · EPSS 62.2% · published 2025-06-17
- CVE-2025-22226 — CISA KEV · CVSS 7.1 high · EPSS 3.5% · published 2025-03-04
- CVE-2023-28204 — CISA KEV · CVSS 6.5 medium · EPSS 0.0% · published 2023-06-23
- CVE-2023-42916 — CISA KEV · CVSS 6.5 medium · EPSS 0.0% · published 2023-11-30
- CVE-2026-10881 — CVSS 9.6 critical · EPSS 0.3% · published 2026-06-04
- CVE-2026-14416 — CVSS 9.6 critical · EPSS 0.2% · published 2026-07-01
- CVE-2026-7482 — CVSS 9.1 critical · EPSS 1.0% · published 2026-05-04
- CVE-2026-58102 — CVSS 9.1 critical · EPSS 0.1% · published 2026-07-13
- CVE-2026-9121 — CVSS 8.8 high · EPSS 0.0% · published 2026-05-20
- CVE-2026-0799 — CVSS 8.7 high · EPSS 0.1% · published 2026-09-05
- CVE-2026-85455 — CVSS 8.2 high · EPSS 0.3% · published 2026-09-03
- CVE-2024-39720 — CVSS 8.2 high · EPSS 0.3% · published 2024-10-31
- CVE-2026-90560 — CVSS 8.2 high · published 2026-09-12
- CVE-2019-16098 — CVSS 7.8 high · EPSS 19.8% · published 2019-09-11
- CVE-2023-36424 — CVSS 7.8 high · EPSS 12.1% · published 2023-11-14
- CVE-2026-8451 — CVSS 7.5 high · EPSS 0.5% · published 2026-06-30
- CVE-2026-10817 — CVSS 7.5 high · EPSS 0.4% · published 2026-06-30
- CVE-2026-85444 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-03
- CVE-2026-66360 — CVSS 7.5 high · EPSS 0.2% · published 2026-07-30
- CVE-2026-67865 — CVSS 7.5 high · EPSS 0.2% · published 2026-08-05
- CVE-2026-26127 — CVSS 7.5 high · EPSS 0.1% · published 2026-03-10
- CVE-2026-5946 — CVSS 7.5 high · EPSS 0.0% · published 2026-05-20
- CVE-2026-76870 — CVSS 7.1 high · EPSS 0.3% · published 2026-09-15
- CVE-2026-56210 — CVSS 7.1 high · published 2026-06-19
- CVE-2026-10848 — CVSS 7 high · EPSS 0.1% · published 2026-08-02
- CVE-2026-57979 — CVSS 6.5 medium · EPSS 0.6% · published 2026-07-14
- CVE-2026-73324 — CVSS 6.5 medium · EPSS 0.3% · published 2026-09-09
- CVE-2026-61893 — CVSS 6.5 medium · EPSS 0.2% · published 2026-07-30
- CVE-2026-63550 — CVSS 6.5 medium · EPSS 0.2% · published 2026-07-30
- CVE-2026-56758 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-66349 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-65421 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-66364 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-66369 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-66720 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-30
- CVE-2026-50811 — CVSS 6.5 medium · EPSS 0.1% · published 2026-07-07
- CVE-2026-9122 — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-20
- CVE-2026-101204 — CVSS 6.3 medium · EPSS 0.2% · published 2026-09-28
Affected vendors
Threat activity
61 tracked threats cite CWE-125; the 25 most recent are listed.
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)CRITICAL
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV CatalogCRITICAL
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)CRITICAL
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)HIGH
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code AccessHIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)HIGH
- Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write, chained with Dolby decoder RCE (CVE-2025-54957)CRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- "When Agentic Glue Melts": Five workerd Memory-Corruption Flaws Enable Cross-Tenant Secret Theft and Code Mode Sandbox Escape on Cloudflare WorkersCRITICAL
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM EscapeCRITICAL
- GitLab RCE Chain via Malicious Jupyter Notebooks Exploiting Oj Ruby JSON Parser FlawsCRITICAL
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation WaveCRITICAL
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)HIGH
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)HIGH
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion DemandsMEDIUM
- Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)HIGH
- Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905)HIGH
- Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch TuesdayMEDIUM
Mitigations
- Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
- Architecture and Design / Language Selection: Use a language that provides appropriate memory abstractions.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Fuzzing (effectiveness: High): Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- Automated Dynamic Analysis (effectiveness: Moderate): Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.