VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-62703Medium· 5.5
1mo ago

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.40%via NVD
CVE-2026-61924Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-61921Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-61918Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-59128Medium· 5.5
1mo ago

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-72522Medium· 6.2
1mo ago

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

▾ SunlitEPSS 0.18%via NVD
CVE-2026-15534Medium· 5.7
1mo ago

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

▾ SunlitRed Hat · perlEPSS 0.26%via NVD
CVE-2026-65819High· 7.5
1mo ago

gopacket provides packet processing capabilities for Go

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded …

▾ TwilightRed Hat · Network Observability (NETOBSERV) 1.12.3EPSS 0.66%via NVD
CVE-2026-66151Medium· 5.5
1mo ago

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

▾ SunlitEPSS 0.16%via NVD
CVE-2026-43630Medium· 6.5
1mo ago

llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated c…

llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated c…

▾ Sunlitggml · llama.cppEPSS 0.50%via NVD
CVE-2026-43628High· 7.8
1mo ago

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry…

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry…

▾ Twilightggml · llama.cppEPSS 0.23%via NVD
CVE-2026-7405Medium· 5.5
1mo ago

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service

▾ Sunlitautodesk · advance_steelEPSS 0.16%via NVD
CVE-2026-5856High· 7.1
1mo ago

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from the attacker-cont…

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from the attacker-cont…

▾ TwilightEPSS 0.29%via NVD
CVE-2026-5855High· 7.5
1mo ago

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterate…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-11803High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary co…

▾ Twilightautodesk · revitEPSS 0.19%via NVD
CVE-2026-71498Medium· 5.1
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…

▾ SunlitRed Hat · re2EPSS 0.17%via NVD
CVE-2026-67865High· 7.5
1mo ago

S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling

S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service

▾ TwilightEPSS 0.76%via NVD
CVE-2026-45705Medium· 5.3
1mo ago

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching …

▾ SunlitEPSS 0.51%via NVD
CVE-2026-70598Low· 3.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully valid…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-69244High· 7.5
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.53%via NVD
CVE-2026-20489None
1mo ago

In display, there is a possible information disclosure due to an integer overflow

In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploit…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-20488None
1mo ago

In display, there is a possible information disclosure due to a missing bounds check

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for expl…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-20479None
1mo ago

In Modem, there is a possible out of bounds read due to a missing bounds check

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privilege…

▾ SunlitEPSS 0.71%via NVD
CVE-2026-10848High· 7.0
1mo ago

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(…

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-67306Medium· 5.4
1mo ago

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c. Only the 1-byt…

▾ Sunlitfreerdp · freerdpEPSS 0.38%via NVD
CVE-2026-67301High· 7.5
1mo ago

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_Polygo…

▾ Twilightfreerdp · freerdpEPSS 0.65%via NVD
CVE-2026-67291High· 7.5
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via NVD
CVE-2026-67290High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-66401Low· 2.1
1mo ago

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera c…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-10773Medium· 5.4
1mo ago

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SI…

▾ SunlitEPSS 0.27%via NVD
CWE-125 vulnerabilities (CVEs) — page 19 · VulnSea