VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-49509Medium· 4.4
3w ago

Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.

Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.

▾ SunlitEPSS 0.15%via NVD
CVE-2026-85455High· 8.2
3w ago

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send…

▾ TwilightEPSS 0.67%via NVD
CVE-2026-64200High· 7.8
3w ago

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an …

▾ Twilightni · dasylabEPSS 0.16%via NVD
CVE-2026-64199High· 7.8
3w ago

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a …

▾ Twilightni · dasylabEPSS 0.16%via NVD
CVE-2026-64198High· 7.8
3w ago

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requir…

▾ Twilightni · dasylabEPSS 0.16%via NVD
CVE-2026-84968Medium· 5.3
3w ago

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is …

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is …

▾ Sunlitmongodb · php_driverEPSS 0.33%via NVD
CVE-2026-85052Low· 3.1
3w ago

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-85444High· 7.5
3w ago

MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length

MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leadi…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-85090Medium· 5.4
3w ago

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame ge…

▾ Sunlitfreerdp · freerdpEPSS 0.43%via NVD
CVE-2026-71222Medium· 5.3
3w ago

A heap out-of-bounds read vulnerability was found in gfs2-utils

A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory con…

▾ Sunlitredhat · enterprise_linuxEPSS 0.14%via NVD
CVE-2026-84484High· 7.5PoC
3w ago

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the L…

▾ Midnightnasa-jpl · ION-DTNEPSS 0.87%via NVD
CVE-2026-52295Low· 2.9
3w ago

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.18%via NVD
CVE-2026-19315None
1mo ago

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-82072High· 8.8
1mo ago

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-81334Medium· 6.1
1mo ago

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in src-lib/darknet_network.cpp as xcalloc(net.n, sizeof(Darknet::Layer)), sized to ex…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-79020Medium· 4.3⚖ disputed
1mo ago

chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)

An out of bounds read flaw was found in the Skia component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514017820

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.37%via CSAF
CVE-2026-79241Medium· 6.5
1mo ago

Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.32%via CVEORG
CVE-2026-79270High· 7.4
1mo ago

chromium-browser: angle: Chromium-browser: Memory disclosure via uninitialized resource in ANGLE (CVE-2026-79270)

A flaw was found in chromium-browser. A remote attacker could exploit an uninitialized resource vulnerability in ANGLE by crafting a malicious HTML page. This could allow the attacker to read sensitive memory outside of the browser's secur…

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.35%via CSAF
CVE-2026-59985Medium· 5.5PoC
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-61555Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. Th…

▾ SunlitAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-65979Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compr…

▾ SunlitRed HatEPSS 0.18%via NVD
CVE-2026-59983Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.17%via NVD
CVE-2026-59189High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.42%via NVD
CVE-2026-24225Medium· 6.0
1mo ago

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.

▾ Sunlitnvidia · dgx_spark_uefiEPSS 0.13%via NVD
CVE-2026-71441Medium· 5.5
1mo ago

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user i…

▾ Sunlitadobe · illustratorEPSS 0.26%via NVD
CVE-2026-16234High· 7.8
1mo ago

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted V…

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted V…

▾ Twilightni · labviewEPSS 0.13%via NVD
CVE-2021-47996High· 7.5
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ TwilightRed HatEPSS 0.50%via NVD
CVE-2026-59981High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library retu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.42%via NVD
CVE-2026-75370Medium· 6.5
1mo ago

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

▾ SunlitEPSS 0.36%via NVD
CVE-2026-75369High· 7.1
1mo ago

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

▾ TwilightEPSS 0.28%via NVD
CWE-125 vulnerabilities (CVEs) — page 15 · VulnSea