VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-39979Medium· 6.5
5mo ago

jq is a command-line JSON processor

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input …

▾ Sunlitjqlang · jqEPSS 0.82%via NVD
CVE-2026-40025Medium· 4.4
5mo ago

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past…

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past…

▾ Sunlitsleuthkit · the_sleuth_kitEPSS 0.18%via NVD
CVE-2026-5913High· 8.1
5mo ago

Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page

Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-5907High· 8.1
5mo ago

Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file

Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-5886Medium· 5.3
5mo ago

Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page

Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-5873High· 8.8
5mo ago

Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-28386High· 7.5
5mo ago

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds…

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds…

▾ Twilightopenssl · opensslEPSS 0.33%via NVD
CVE-2026-32864High· 7.8
5mo ago

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation require…

▾ Twilightni · labviewEPSS 0.19%via NVD
CVE-2026-32863High· 7.8
5mo ago

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploit…

▾ Twilightni · labviewEPSS 0.19%via NVD
CVE-2026-34588High· 8.6
5mo ago

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.57%via CVEORG
CVE-2026-31395High· 7.1
5mo ago

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-su…

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-su…

▾ Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-31393High· 8.1
5mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + resul…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + resul…

▾ Twilightlinux · linux_kernelEPSS 0.42%via NVD
CVE-2026-23456High· 8.2
5mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(b…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(b…

▾ Twilightlinux · linux_kernelEPSS 0.52%via NVD
CVE-2026-23455Critical· 9.1
5mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it…

▾ Midnightlinux · linux_kernelEPSS 1.3%via NVD
CVE-2026-35038Medium· 6.5
5mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated u…

▾ Sunlitsignalk · signal_k_serverEPSS 0.41%via NVD
CVE-2026-2394Medium· 6.5
5mo ago

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 befo…

▾ Sunlitrti · connext_professionalEPSS 0.16%via NVD
CVE-2026-34235Critical· 9.1
6mo ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability Structu…

▾ Midnightteluu · pjsipEPSS 0.54%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-32286High· 7.5PoC
6mo ago

The DataRow.Decode function fails to properly validate field lengths

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

▾ Midnightjackc · pgproto3EPSS 0.92%via NVD
CVE-2026-4647Medium· 6.1
6mo ago

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type valu…

▾ Sunlitgnu · binutilsEPSS 0.17%via NVD
CVE-2026-4424High· 7.5
6mo ago

A flaw was found in libarchive

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote atta…

▾ Twilightlibarchive · libarchiveEPSS 1.1%via NVD
CVE-2026-3442Medium· 6.1
6mo ago

A flaw was found in GNU Binutils

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafte…

▾ Sunlitgnu · binutilsEPSS 0.19%via NVD
CVE-2026-3441Medium· 6.1
6mo ago

A flaw was found in GNU Binutils

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a speciall…

▾ Sunlitgnu · binutilsEPSS 0.19%via NVD
CVE-2025-70330Low· 3.3PoC
6mo ago

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds …

▾ TwilightEPSS 0.15%via NVD
CVE-2026-27269High· 7.8
6mo ago

Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure

Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerabi…

▾ Twilightadobe · premiere_proEPSS 0.29%via NVD
CVE-2026-27219Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure

Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exp…

▾ Sunlitadobe · substance_3d_painterEPSS 0.26%via NVD
CVE-2026-27216Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exp…

▾ Sunlitadobe · substance_3d_painterEPSS 0.26%via NVD
CVE-2026-21365Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exp…

▾ Sunlitadobe · substance_3d_painterEPSS 0.14%via NVD
CVE-2026-2771Critical· 9.8
7mo ago

Undefined behavior in the DOM: Core & HTML component

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

▾ Midnightmozilla · firefoxEPSS 0.61%via NVD
CVE-2026-2243Medium· 5.1
7mo ago

A flaw was found in QEMU

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

▾ SunlitEPSS 0.12%via NVD
CWE-125 vulnerabilities (CVEs) — page 27 · VulnSea