VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-44820High· 7.8
3mo ago

Microsoft Excel Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-44821Medium· 5.5
3mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.60%via CVEORG
CVE-2026-45607High· 8.4
3mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-45606Medium· 5.5
3mo ago

Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-45634Medium· 5.5
3mo ago

Windows DHCP Client Information Disclosure Vulnerability

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-44822High· 8.2
3mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.60%via CVEORG
CVE-2026-45457High· 7.8
3mo ago

Microsoft Word Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45455Low· 3.3
3mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.76%via CVEORG
CVE-2026-45604Medium· 5.5
3mo ago

Windows Managed Installer Information Disclosure Vulnerability

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 version 23H2EPSS 0.40%via CVEORG
CVE-2026-45608Medium· 6.8
3mo ago

Windows DHCP Client Information Disclosure Vulnerability

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.38%via CVEORG
CVE-2026-42837High· 7.8
3mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-42908High· 7.5
3mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.0%via CVEORG
CVE-2026-42968Medium· 5.5
3mo ago

Windows Telephony Server Information Disclosure Vulnerability

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-44808High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-45639High· 7.5
3mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Remote Desktop client for Windows DesktopEPSS 1.0%via CVEORG
CVE-2026-44814Medium· 5.5
3mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 version 26H1EPSS 0.40%via CVEORG
CVE-2026-42914Medium· 5.3
3mo ago

Windows Kerberos Denial of Service Vulnerability

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.83%via CVEORG
CVE-2026-48566Medium· 5.5
3mo ago

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ Sunlitmicrosoft · windows_11_24h2EPSS 0.40%via NVD
CVE-2026-44185High· 7.3
3mo ago

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

▾ Twilightapache · http_serverEPSS 1.8%via NVD
CVE-2026-50262Medium· 5.5
3mo ago

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes()

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to informa…

▾ Sunlitx.org · x_serverEPSS 0.18%via NVD
CVE-2026-7764Medium· 6.8
3mo ago

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap m…

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap m…

▾ Sunlitmorsemicro · halowlink_2_firmwareEPSS 0.19%via NVD
CVE-2026-46344Medium· 5.3
4mo ago

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. …

▾ Sunlitopenquantumsafe · liboqsEPSS 0.30%via NVD
CVE-2026-46130High· 7.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never spli…

In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never spli…

▾ Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-46140High· 7.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to struct btmtk_hci_wmt_evt (7 byte…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to struct btmtk_hci_wmt_evt (7 byte…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-46033High· 7.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN …

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN …

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-41071High· 8.1
4mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow …

▾ Twilightstruktur · libheifEPSS 0.44%via NVD
CVE-2026-41069Medium· 6.5
4mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_…

▾ Sunlitstruktur · libheifEPSS 0.39%via NVD
CVE-2026-43618High· 8.1
4mo ago

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…

▾ Twilightsamba · rsyncEPSS 0.80%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-34663Medium· 5.5
4mo ago

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploit…

▾ Sunlitadobe · illustratorEPSS 0.26%via NVD
CWE-125 vulnerabilities (CVEs) — page 25 · VulnSea