VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-65969Medium· 5.5
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is proce…

▾ SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-63635Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal va…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-63420Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer sto…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-59956Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffi…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-16512Low· 3.1
1w ago

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-16514Medium· 4.3
1w ago

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attac…

▾ Sunlitzephyrproject · zephyrEPSS 0.24%via NVD
CVE-2026-93599High· 7.5PoC
1w ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

▾ Midnightrustls · webpkiEPSS 0.49%via NVD
CVE-2026-93331High· 7.3
1w ago

A vulnerability was identified in GPAC 26.08-DEV

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-54633Medium· 6.9
1w ago

PoDoFo is a C++17 PDF manipulation library

PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in src/podofo/main/Pd…

▾ Sunlitpodofo · podofoEPSS 0.18%via NVD
CVE-2026-50291Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application l…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-73638Medium· 6.2
1w ago

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-93376Medium· 6.3
1w ago

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.11%via NVD
CVE-2026-44235Medium· 6.5PoC
1w ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…

▾ Twilightalanxz · rabbitmq-cEPSS 0.36%via NVD
CVE-2026-52836High· 8.7
1w ago

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS)

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS UDP submessage w…

▾ TwilightOpenDDS · OpenDDSEPSS 0.74%via NVD
CVE-2026-54579Low· 2.3
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker abl…

▾ SunlitMidnightBSD · mportEPSS 0.16%via NVD
CVE-2026-90407High· 7.7⚖ disputed
1w ago

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infras…

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infras…

▾ TwilightLinux · LinuxEPSS 0.19%via NVD
CVE-2026-92925High· 7.1
1w ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

▾ TwilightRed Hat · redis:7EPSS 0.57%via NVD
CVE-2026-25282High· 7.9
1w ago

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.06%via NVD
CVE-2026-92475Medium· 5.3PoC
1w ago

A weakness has been identified in GPAC 26.08-DEV

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires loca…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-73462Medium· 6.5
1w ago

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

▾ SunlitArista Networks · EOSEPSS 0.28%via NVD
CVE-2026-56719Medium· 6.5
1w ago

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

▾ SunlitMikroTik · RouterOSEPSS 0.39%via NVD
CVE-2026-89846Critical· 9.1⚖ disputed
1w ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_inf…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_inf…

▾ MidnightLinux · LinuxEPSS 0.71%via NVD
CVE-2026-76151Medium· 4.6
1w ago

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

▾ Sunlitqt · qtEPSS 0.67%via NVD
CVE-2026-73436Medium· 6.5
1w ago

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

▾ SunlitArista Networks · EOSEPSS 0.27%via NVD
CVE-2026-92255Medium· 5.4
1w ago

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in…

▾ SunlitNetcore · NR255-VEPSS 0.35%via NVD
CVE-2026-76870High· 7.1
1w ago

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trig…

▾ TwilightNetcore · NR255-VEPSS 0.40%via NVD
CVE-2026-91733High· 8.3
1w ago

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-91726Medium· 4.7⚖ disputed
1w ago

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-92240Critical· 9.1⚖ disputed
1w ago

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnera…

▾ Midnightmozilla · thunderbirdEPSS 0.63%via NVD
CVE-2026-92239High· 8.1⚖ disputed
1w ago

A maliciously constructed IMAP line could cause an out-of-bounds buffer read

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ Twilightmozilla · thunderbirdEPSS 0.41%via NVD
CWE-125 vulnerabilities (CVEs) — page 3 · VulnSea