CWE-125
CVEs classified under CWE-125, newest first.
940 CVEsRSS
CVE-2026-68779Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68778Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68777Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67645Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67636Critical· 9.0Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67633Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
CVE-2026-67630Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67629Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67624Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67389Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67369Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-62706High· 8.8Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-56198High· 7.8Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-82066Medium· 4.3A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server
A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the…
CVE-2026-86714Medium· 5.4PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read be…
CVE-2026-86303High· 7.3PoCA vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f
A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation can lead to out-of-bounds read. The attack can be exec…
CVE-2026-86288Medium· 6.3PoCA vulnerability has been found in ModelCloud GPTQModel up to 7.2.0
A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argu…
CVE-2026-20518Medium· 4.4In geniezone, there is a possible information disclosure due to a missing bounds check
In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploi…
CVE-2026-86227Low· 3.1PoCA weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1
A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate t…
CVE-2026-31912Medium· 5.5libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer
libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular …
CVE-2026-18238Medium· 5.0The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process…
CVE-2026-0799High· 8.7In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use c…
CVE-2025-15647Medium· 5.5PoCCDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles
CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenera…
CVE-2025-15614Low· 3.3ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files
ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated h…
CVE-2026-86137Low· 2.9In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
CVE-2026-85698Medium· 5.5Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation
Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modifi…
CVE-2026-85769Medium· 6.5PoCA flaw was found in libtpms, a library that provides software TPM 2.0 emulation
A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized sk…
CVE-2026-16660Medium· 5.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
CVE-2026-85522Medium· 5.3A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0
A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argume…
CVE-2026-85505High· 7.5ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which h…
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which h…