VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-10645Medium· 4.9
3mo ago

Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state

Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de…

▾ Sunlitzephyrproject · zephyrEPSS 0.16%via NVD
CVE-2026-12892Medium· 4.4
3mo ago

A flaw was found in GStreamer's gst-plugins-bad package

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happ…

▾ Sunlitgstreamer · gstreamerEPSS 0.16%via NVD
CVE-2026-52910High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog a…

▾ Midnightlinux · linux_kernelEPSS 0.11%via NVD
CVE-2026-56210High· 7.1
3mo ago

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the co…

▾ TwilightRed Hat · aomEPSS 0.58%via NVD
GHSA-5prr-v3j2-97mhMedium
3mo ago

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

▾ Sunlitnokogiri · nokogirivia GHSA
CVE-2026-54500Medium· 5.3
3mo ago

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

▾ Sunlitoj · ojEPSS 0.33%via GHSA
CVE-2026-54592High· 7.5
3mo ago

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

▾ Twilightoj · ojEPSS 0.46%via GHSA
CVE-2025-15661Medium· 6.5
3mo ago

libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory cont…

▾ Sunlitlibssh2 · libssh2EPSS 0.65%via CVEORG
CVE-2026-12568Medium· 6.5
3mo ago

BBOT: Arbitrary File Write in postman_download Module

BBOT: Arbitrary File Write in postman_download Module

▾ Sunlitbbot · bbotEPSS 0.25%via GHSA
CVE-2026-3894Critical· 9.1
3mo ago

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 befor…

▾ Midnightrti · connext_professionalEPSS 0.33%via NVD
CVE-2026-30802High· 8.2
3mo ago

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*.

▾ Twilightrti · connext_microEPSS 0.43%via NVD
CVE-2026-0157Medium· 4.3
3mo ago

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.17%via NVD
CVE-2026-0165Medium· 6.5
3mo ago

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0155Medium· 5.3
3mo ago

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploit…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0142Medium· 4.0
3mo ago

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed …

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0141Medium· 5.3
3mo ago

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl…

▾ Sunlitgoogle · androidEPSS 0.21%via NVD
CVE-2026-0140Medium· 4.3
3mo ago

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0130Medium· 4.3
3mo ago

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0136High· 7.5
3mo ago

In Modem, there is a possible out of bounds read due to a missing bounds check

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.27%via NVD
CVE-2026-4367Medium· 5.5
3mo ago

A flaw was found in libXpm

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper valid…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-12298Medium· 5.4
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-0128Medium· 6.5⚖ disputed
3mo ago

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for explo…

▾ Sunlitgoogle · androidEPSS 0.19%via NVD
CVE-2026-53704High· 7.1
3mo ago

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using…

▾ TwilightRed Hat · gstreamer1-plugins-ugly-freeEPSS 0.46%via NVD
CVE-2026-52719High· 7.1
3mo ago

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could tr…

▾ TwilightEPSS 0.63%via NVD
GHSA-537c-gmf6-5ccfHigh· 7.5
3mo ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Twilightcryptography · cryptographyvia OSV
CVE-2026-54413High· 8.2
3mo ago

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-54412High· 8.2
3mo ago

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

▾ TwilightEPSS 0.72%via NVD
GHSA-36hh-v3qg-5jq4High
3mo ago

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

▾ Twilightpyo3 · pyo3via GHSA
CVE-2026-48040Medium
3mo ago

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringsslEPSS 0.29%via GHSA
CVE-2026-45485Low· 3.3
3mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.56%via CVEORG
CWE-125 vulnerabilities (CVEs) — page 24 · VulnSea