VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-34961Medium· 6.2
4mo ago

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c. Attackers can supply a malicious ex…

▾ Sunlitpengutronix · bareboxEPSS 0.22%via NVD
CVE-2026-34960Medium· 6.5
4mo ago

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on…

▾ Sunlitpengutronix · bareboxEPSS 0.38%via NVD
CVE-2026-4891Medium· 5.3
4mo ago

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

▾ SunlitEPSS 0.84%via NVD
CVE-2026-8177High· 7.5
4mo ago

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.88%via NVD
CVE-2026-7568High· 7.5
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string.…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string.…

▾ Twilightphp · phpEPSS 0.84%via NVD
CVE-2026-3508Medium· 6.8
4mo ago

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section o…

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section o…

▾ SunlitASUS · ASUS System Control InterfaceEPSS 0.14%via NVD
CVE-2026-8092High· 8.1
4mo ago

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run a…

▾ Twilightmozilla · firefoxEPSS 0.54%via NVD
CVE-2026-42216Critical· 9.1PoC
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…

▾ Abyssalopenexr · openexrEPSS 0.71%via NVD
CVE-2026-43197Critical· 9.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit…

▾ Midnightlinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-43112High· 8.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., …

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., …

▾ Twilightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2026-43071Critical· 9.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault…

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault…

▾ Midnightlinux · linux_kernelEPSS 0.73%via NVD
CVE-2026-41607Medium· 6.5⚖ disputed
5mo ago

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Sunlitapache · thriftEPSS 0.90%via NVD
CVE-2026-41604High· 8.2
5mo ago

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 1.2%via NVD
CVE-2026-31641High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and ticket length from the XDR token as u32 values and passes each…

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and ticket length from the XDR token as u32 values and passes each…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-31449High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_indexes ext4_ext_correct_indexes() walks up the extent tree correcting index entries when the first extent in a leaf is…

In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_indexes ext4_ext_correct_indexes() walks up the extent tree correcting index entries when the first extent in a leaf is…

▾ Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-5720Critical· 9.1
5mo ago

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attacker…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-27931Medium· 5.5
5mo ago

Windows GDI Information Disclosure Vulnerability

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.54%via CVEORG
CVE-2026-32188High· 7.1
5mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.53%via CVEORG
CVE-2026-33096High· 7.5
5mo ago

HTTP.sys Denial of Service Vulnerability

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 1.2%via CVEORG
CVE-2026-33822Medium· 6.1
5mo ago

Microsoft Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.46%via CVEORG
CVE-2026-26156High· 7.8
5mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-26153High· 7.8
5mo ago

Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-27930Medium· 5.5
5mo ago

Windows GDI Information Disclosure Vulnerability

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-32076High· 7.8
5mo ago

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-56370Low· 3.3
5mo ago

ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts

ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.18%via GHSA
CVE-2026-5713None
5mo ago

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that pro…

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that pro…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-27294High· 7.8
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vul…

▾ Twilightadobe · framemakerEPSS 0.29%via NVD
CVE-2026-27287High· 7.8
5mo ago

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnera…

▾ Twilightadobe · incopyEPSS 0.29%via NVD
CVE-2026-27289High· 7.8
5mo ago

Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure

Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln…

▾ Twilightadobe · photoshopEPSS 0.29%via NVD
CVE-2026-39956Medium· 6.1
5mo ago

jq is a command-line JSON processor

jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relie…

▾ Sunlitjqlang · jqEPSS 0.17%via NVD
CWE-125 vulnerabilities (CVEs) — page 26 · VulnSea