VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-62959None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single or…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-54908Medium
1mo ago

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

▾ Sunlitpion · github.com/pion/dtls/v3EPSS 0.54%via GHSA
CVE-2026-17701Critical· 9.6
1mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chrom…

▾ Midnightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-55777None
1mo ago

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source o…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-66360High· 7.5
1mo ago

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zer…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-66349Medium· 6.5
1mo ago

The MMS server connection handler contains a flaw in its processing of BER-encoded request data

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its int…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-63033Medium· 6.5
1mo ago

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-61893Medium· 6.5
1mo ago

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-56758Medium· 6.5
1mo ago

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to rea…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-17678High· 8.8
1mo ago

Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-58216Medium· 5.3
1mo ago

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structur…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-67550Medium· 5.7
1mo ago

re2 provides Node.js bindings for Google's RE2 regular expression engine

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and spl…

▾ Sunlitre2 · re2EPSS 0.16%via NVD
CVE-2026-17550Medium· 5.5
2mo ago

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-16465Medium· 6.1
2mo ago

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-43738Medium· 5.5
2mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset c…

▾ Sunlitapple · macosEPSS 0.17%via NVD
CVE-2026-64411High· 7.1
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_ta…

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_ta…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64407High· 7.1
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() During the v3 firmware download the controller sends a v3_data_req with a 32 bit offset a…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() During the v3 firmware download the controller sends a v3_data_req with a 32 bit offset a…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64364High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_co…

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_co…

▾ Twilightlinux · linux_kernelEPSS 0.35%via NVD
CVE-2026-64320Critical· 9.1⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Pag…

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Pag…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.75%via NVD
CVE-2026-64319Critical· 9.1⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (ha…

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (ha…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.52%via NVD
CVE-2026-64317High· 7.1
2mo ago

In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the SL record get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length compo…

In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the SL record get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length compo…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64287High· 8.2
2mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.18%via NVD
CVE-2026-64277High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3…

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-64276High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at mo…

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at mo…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
GHSA-hwf3-r46v-5ggxLow· 2.9
2mo ago

ImageMagick: Information Disclosure when printing profiles with debug enabled

ImageMagick: Information Disclosure when printing profiles with debug enabled

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-43820High· 7.7
2mo ago

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer…

▾ Twilightapple · swiftnio_sslEPSS 0.11%via NVD
CVE-2026-65918High· 7.1PoC
2mo ago

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or trunc…

▾ Midnightlinuxfoundation · torchvisionEPSS 0.45%via NVD
CVE-2026-59842Low· 3.7
2mo ago

A flaw was found in libssh

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could al…

▾ Sunlitlibssh · libsshEPSS 0.49%via NVD
CVE-2026-59198Medium· 6.5
2mo ago

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

▾ Sunlitpillow · pillowEPSS 0.50%via OSV
CVE-2026-64069Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single read subrequests When the preparation of a new subrequest for a read fails, if the subrequest has already been added to the…

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single read subrequests When the preparation of a new subrequest for a read fails, if the subrequest has already been added to the…

▾ Midnightlinux · linux_kernelEPSS 0.65%via NVD
CWE-125 vulnerabilities (CVEs) — page 20 · VulnSea