VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-91817Medium· 6.1
4d ago

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-91810Medium· 6.1
4d ago

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bo…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-91808Medium· 6.1
4d ago

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and …

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-91807Medium· 6.1
4d ago

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow,…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-88345High· 7.5PoC
5d ago

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer afte…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-77558High· 7.5
5d ago

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77556High· 7.5
5d ago

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-75656Medium· 5.5
5d ago

Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user intera…

▾ Sunlitadobe · bridgeEPSS 0.15%via NVD
CVE-2026-11389Medium· 6.8
5d ago

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Co…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-18458Medium· 6.8
5d ago

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Co…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-18626Medium· 6.8
5d ago

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 bef…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-81881Low· 3.3
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata sect…

▾ Sunlitradare · radare2EPSS 0.13%via NVD
CVE-2026-81883Low· 3.3PoC
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields imm…

▾ Twilightradareorg · radare2EPSS 0.18%via NVD
CVE-2026-81882Low· 3.3
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized U…

▾ Sunlitradare · radare2EPSS 0.12%via NVD
CVE-2026-81879Medium· 5.5PoC
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but s…

▾ Twilightradare · radare2EPSS 0.21%via NVD
CVE-2026-81884Low· 2.5PoC
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a fi…

▾ Twilightradareorg · radare2EPSS 0.17%via NVD
CVE-2026-63272Medium· 5.4
5d ago

LibreOffice can import WMF graphics, which may be embedded in documents

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63279Medium· 5.4
5d ago

LibreOffice can import PICT images, which may be embedded in documents

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63274Medium· 5.4
5d ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-74765Medium· 6.5
5d ago

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed in…

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed in…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-17054Medium· 5.3
6d ago

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task()

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and …

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-57228High· 8.2
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a hea…

▾ TwilightOISF · suricataEPSS 0.57%via NVD
CVE-2026-61721High· 8.0
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_valid…

▾ TwilightFluidSynth · fluidsynthEPSS 0.19%via NVD
CVE-2026-61714High· 7.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap…

▾ TwilightFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-75895High· 7.5
1w ago

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

▾ TwilightOsmocom · libsmpp34EPSS 0.42%via NVD
CVE-2026-11726High· 8.1
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.33%via NVD
CVE-2026-73863High· 7.0PoC
1w ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTI…

▾ Midnightnanomq · nanomqEPSS 0.35%via NVD
CVE-2026-84451Medium· 6.5
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition…

▾ Sunlitstrukturag · libheifEPSS 0.45%via NVD
CVE-2026-84449Low· 3.7PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

▾ Twilightstrukturag · libheifEPSS 0.43%via NVD
CVE-2026-84448Medium· 4.0PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals…

▾ Twilightstrukturag · libheifEPSS 0.15%via NVD
CWE-125 vulnerabilities (CVEs) — page 2 · VulnSea