cwe-125
Safeguard articles tagged "cwe-125" — guides, analysis, and best practices for software supply chain and application security.
21 articles
CVE-2025-5419: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
CVE-2025-5419 affects Google Chromium V8 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-06-05.
CVE-2025-5777: Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
CVE-2025-5777 affects Citrix NetScaler ADC and Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-10.
CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
CVE-2026-3055 affects Citrix NetScaler and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-30.
CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability
CVE-2023-36424 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-13.
CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
CVE-2026-11645 affects Google Chromium V8 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-09.
Cloudbleed (2017): A Parser Bug That Leaked Other Customers Data Into Web Pages
A factual retrospective on Cloudbleed, a 2017 buffer overrun in Cloudflare HTML parsing that leaked adjacent memory, including other customers private data, into responses that search engines then cached.
Citrix Bleed (CVE-2023-4966): Stolen Sessions That Walked Past MFA
A factual look at Citrix Bleed, a 2023 buffer over-read in NetScaler appliances that leaked valid session tokens, allowing attackers to hijack authenticated sessions without credentials or a second factor.
Heartbleed (CVE-2014-0160): What Happened and What It Changed
A retrospective on the OpenSSL Heartbleed bug, its disclosure in April 2014, and its lasting effect on how the industry handles memory-safety bugs in widely-used crypto libraries.
Out-of-Bounds Read Vulnerabilities (CWE-125) Explained
How out-of-bounds read vulnerabilities (CWE-125) leak memory instead of crashing programs, why Heartbleed and Cloudbleed happened, and how to catch them in your dependencies.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.