VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-56136Medium· 4.7
1mo ago

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read oper…

▾ SunlitEPSS 0.12%via NVD
GHSA-3gjw-f78c-vvpwMedium
1mo ago

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

▾ Sunlittokio-postgres · tokio-postgresvia GHSA
CVE-2026-77219High· 7.1
1mo ago

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image load…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-54789High· 7.5
1mo ago

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.72%via NVD
CVE-2026-50278Medium· 6.5
1mo ago

iccDEV provides a set of libraries and tools for working with ICC color management profiles

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing I…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-76641High· 7.5
1mo ago

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.61%via NVD
CVE-2026-55894None
1mo ago

Capstone is a disassembly framework

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific de…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-54616High· 7.1
1mo ago

NanaZip is the 7-Zip derivative intended for the modern Windows experience

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHa…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-53587High· 7.5PoC
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in…

▾ Midnightlibgit2 · libgit2EPSS 0.68%via NVD
CVE-2026-63383High· 8.7PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates u…

▾ Midnightlibevent · libeventEPSS 0.52%via NVD
CVE-2026-76882Medium· 4.7PoC
1mo ago

Out-of-bounds Read in Wireshark

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76924Medium· 5.5
1mo ago

Out-of-bounds Read in Wireshark

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-55564Medium· 5.4
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malic…

▾ Sunlitfreerdp · freerdpEPSS 0.44%via NVD
CVE-2026-55192High· 8.2
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensio…

▾ Twilightfreerdp · freerdpEPSS 0.59%via NVD
CVE-2026-55648High· 7.5⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-b…

▾ Twilightfreerdp · freerdpEPSS 0.43%via NVD
CVE-2026-23935Medium· 4.9
1mo ago

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

▾ Sunlitzabbix · zabbixEPSS 0.34%via NVD
CVE-2026-50126Medium· 4.0
1mo ago

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safe…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-62292None
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_imag…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-62291Medium· 5.3
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled heap corruption during a normal decode…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-75904Low· 3.3PoC
1mo ago

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static arr…

▾ TwilightKonstanty Bialkowski · libmodplugEPSS 0.17%via NVD
CVE-2026-63632Low· 3.3
1mo ago

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/vers…

▾ Sunlitonnx · onnxEPSS 0.17%via NVD
CVE-2026-59949Medium· 6.5
1mo ago

yawkat LZ4 Java provides LZ4 compression for Java

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.n…

▾ Sunlityawk · at.yawk.lz4:lz4-javaEPSS 0.47%via NVD
CVE-2026-74238High· 7.5
1mo ago

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacen…

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacen…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-71980High· 7.5
1mo ago

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundar…

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundar…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-65349Medium· 6.6PoC
1mo ago

An out-of-bounds read was addressed with improved input validation

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected sys…

▾ Twilightapple · ipadosEPSS 0.15%via NVD
CVE-2026-64784Medium· 4.3⚖ disputed
1mo ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafte…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65832High· 8.2
1mo ago

Deskflow is a keyboard and mouse sharing app

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that th…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-63409High· 8.2
1mo ago

Deskflow is a keyboard and mouse sharing app

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missi…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-49282Medium· 5.1
1mo ago

Capstone is a disassembly framework

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before index…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-73515High· 8.1
1mo ago

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that …

▾ TwilightEPSS 0.57%via NVD
CWE-125 vulnerabilities (CVEs) — page 16 · VulnSea