VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-49794Medium· 4.6
2mo ago

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2026-57432High· 8.4
2mo ago

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size tim…

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size tim…

▾ Twilightperl · perlEPSS 0.20%via NVD
CVE-2026-57158None
2mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/plana…

▾ SunlitEPSS 0.69%via NVD
CVE-2026-57157Medium· 6.5
2mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-11404High· 7.5
2mo ago

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating…

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-54234High· 7.5
2mo ago

vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.62%via CSAF
CVE-2026-56015Critical· 9.1
2mo ago

Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToT…

Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToT…

▾ MidnightEPSS 0.65%via NVD
CVE-2025-11000Medium· 4.4
2mo ago

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

▾ Sunlitopenbabel · openbabelEPSS 0.24%via GHSA
CVE-2026-58011Medium· 6.5PoC
2mo ago

A flaw was found in GLib

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This …

▾ Twilightgnome · glibEPSS 0.82%via NVD
CVE-2026-10652Medium· 4.8
2mo ago

Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR header (type, class, TTL, rdlength) and accepted any attacker-declared rdlength, including on…

Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR header (type, class, TTL, rdlength) and accepted any attacker-declared rdlength, including on…

▾ Sunlitzephyrproject · zephyrEPSS 0.41%via NVD
CVE-2026-57585High· 7.5
2mo ago

msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)

A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by re…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.49%via CSAF
CVE-2026-2704Low· 4.4
2mo ago

Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

▾ Sunlitopenbabel · openbabelEPSS 0.84%via GHSA
CVE-2026-41992High· 7.5⚖ disputed
3mo ago

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array …

▾ Twilightgnu · gzipEPSS 0.56%via NVD
CVE-2026-13522Medium· 4.3
3mo ago

A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14

A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Pe…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-5757High· 7.5
3mo ago

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and…

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-53268High· 8.2
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a dif…

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a dif…

▾ Twilightlinux · linux_kernelEPSS 0.39%via NVD
CVE-2026-53149High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir() does not check that content_offset + content_len fits within block_len for the root d…

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir() does not check that content_offset + content_len fits within block_len for the root d…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53147High· 8.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handle_request() casts the received packet buffer to protocol-specific structs without verify…

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handle_request() casts the received packet buffer to protocol-specific structs without verify…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2026-53230High· 8.7
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using the PF's log_max_current_uc/m…

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using the PF's log_max_current_uc/m…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53224Critical· 9.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remainin…

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remainin…

▾ Midnightlinux · linux_kernelEPSS 0.74%via NVD
CVE-2026-53223High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue

In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue. That assumption is not…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53131Critical· 9.4⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslo…

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslo…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.61%via NVD
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-52942High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with "skb->mac_header != skb-…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with "skb->mac_header != skb-…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53078High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and…

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-52999Critical· 9.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_o…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_o…

▾ Midnightlinux · linux_kernelEPSS 0.82%via NVD
CVE-2026-55654Low· 3.7
3mo ago

A flaw was found in OpenSSH

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the au…

▾ Sunlitopenbsd · opensshEPSS 0.65%via NVD
CVE-2026-12891Medium· 4.3
3mo ago

Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser

A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent mem…

▾ SunlitRed Hat · gstreamer1-plugins-bad-freeEPSS 0.39%via CVEORG
CVE-2026-12969Medium· 5.3
3mo ago

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-lengt…

▾ Sunlitthekelleys · dnsmasqEPSS 0.40%via NVD
CVE-2026-10658High· 7.1
3mo ago

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS SDU head…

▾ Twilightzephyrproject · zephyrEPSS 0.28%via NVD
CWE-125 vulnerabilities (CVEs) — page 23 · VulnSea