VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

809 CVEsRSS

CVE-2026-57228High· 8.2
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a hea…

TwilightOISF · suricataEPSS 0.56%via NVD
CVE-2026-61721High· 8.0
3d ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_valid…

TwilightFluidSynth · fluidsynthEPSS 0.15%via NVD
CVE-2026-61714High· 7.8
3d ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap…

TwilightFluidSynth · fluidsynthEPSS 0.14%via NVD
CVE-2026-75895None
3d ago

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

SunlitOsmocom · libsmpp34EPSS 0.16%via NVD
CVE-2026-11726High· 8.1
3d ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

TwilightIBM · MQ for HPE NonStopEPSS 0.46%via NVD
CVE-2026-73863High· 7.0
3d ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTI…

Twilightnanomq · nanomqEPSS 0.27%via NVD
CVE-2026-84451Medium· 6.5
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition…

Sunlitstrukturag · libheifEPSS 0.45%via NVD
CVE-2026-84449Low· 3.7
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

Sunlitstrukturag · libheifEPSS 0.34%via NVD
CVE-2026-84448Medium· 4.0
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals…

Sunlitstrukturag · libheifEPSS 0.12%via NVD
CVE-2026-65969Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is proce…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.13%via NVD
CVE-2026-63635Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal va…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.15%via NVD
CVE-2026-63420Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer sto…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.13%via NVD
CVE-2026-59956Medium· 6.1PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffi…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-16512Low· 3.1
3d ago

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-16514Medium· 4.3
3d ago

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attac…

Sunlitzephyrproject · zephyrEPSS 0.24%via NVD
CVE-2026-93331High· 7.3
3d ago

A vulnerability was identified in GPAC 26.08-DEV

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of…

TwilightEPSS 0.31%via NVD
CVE-2026-54633Medium· 6.9
4d ago

PoDoFo is a C++17 PDF manipulation library

PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in src/podofo/main/Pd…

Sunlitpodofo · podofoEPSS 0.13%via NVD
CVE-2026-50291Medium· 5.5
4d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application l…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.14%via NVD
CVE-2026-73638None
4d ago

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

SunlitEPSS 0.18%via NVD
CVE-2026-93376Medium· 6.3
4d ago

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.08%via NVD
CVE-2026-44235Medium· 6.5PoC
4d ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…

Twilightalanxz · rabbitmq-cEPSS 0.35%via NVD
CVE-2026-52836High· 8.7
4d ago

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS)

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS UDP submessage w…

TwilightOpenDDS · OpenDDSEPSS 0.41%via NVD
CVE-2026-54579Low· 2.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker abl…

SunlitMidnightBSD · mportEPSS 0.14%via NVD
CVE-2026-92925High· 7.1
4d ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

TwilightRed Hat · pen-drive/pen-drive-scanner-rhel9EPSS 0.34%via NVD
CVE-2026-25282High· 7.9
4d ago

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.10%via NVD
CVE-2026-92475Medium· 5.3
5d ago

A weakness has been identified in GPAC 26.08-DEV

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires loca…

SunlitEPSS 0.14%via NVD
CVE-2026-73462Medium· 6.5
5d ago

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

SunlitArista Networks · EOSEPSS 0.24%via NVD
CVE-2026-56719Medium· 6.5
5d ago

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

SunlitMikroTik · RouterOSEPSS 0.38%via NVD
CVE-2026-76151Medium· 4.6
5d ago

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Sunlitqt · qtEPSS 0.64%via NVD
CVE-2026-73436Medium· 6.5
5d ago

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

SunlitArista Networks · EOSEPSS 0.23%via NVD
CWE-125 vulnerabilities (CVEs) · VulnSea