CWE-125
CVEs classified under CWE-125, newest first.
940 CVEsRSS
CVE-2026-10645Medium· 4.9Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state
Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de…
CVE-2026-12892Medium· 4.4A flaw was found in GStreamer's gst-plugins-bad package
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happ…
CVE-2026-52910High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro
In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog a…
CVE-2026-56210High· 7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the co…
GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-54592High· 7.5Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2025-15661Medium· 6.5libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory cont…
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-3894Critical· 9.1Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 befor…
CVE-2026-30802High· 8.2Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers
Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*.
CVE-2026-0157Medium· 4.3In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0165Medium· 6.5In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…
CVE-2026-0155Medium· 5.3In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check
In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploit…
CVE-2026-0142Medium· 4.0In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed …
CVE-2026-0141Medium· 5.3In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl…
CVE-2026-0140Medium· 4.3In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2026-0130Medium· 4.3In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita…
CVE-2026-0136High· 7.5In Modem, there is a possible out of bounds read due to a missing bounds check
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-4367Medium· 5.5A flaw was found in libXpm
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper valid…
CVE-2026-12298Medium· 5.4Memory safety bug fixed in Firefox 152
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-0128Medium· 6.5⚖ disputedIn RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for explo…
CVE-2026-53704High· 7.1A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using…
CVE-2026-52719High· 7.1An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could tr…
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2026-54413High· 8.2driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…
CVE-2026-54412High· 8.2LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …
GHSA-36hh-v3qg-5jq4HighPyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
CVE-2026-48040Mediumnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVE-2026-45485Low· 3.3Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.