VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-84524Medium· 4.3
1w ago

An out-of-bounds read was addressed with improved bounds checking

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Proce…

▾ Sunlitapple · ipadosEPSS 0.43%via NVD
CVE-2026-84549High· 7.5
1w ago

An out-of-bounds read was addressed with improved bounds checking

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt…

▾ Twilightapple · macosEPSS 0.57%via NVD
CVE-2026-86903Medium· 5.5
1w ago

An out-of-bounds read was addressed with improved input validation

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-65376Medium· 5.5
1w ago

An out-of-bounds read was addressed with improved bounds checking

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-64736High· 7.1
1w ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpec…

▾ Twilightapple · ipadosEPSS 0.16%via NVD
CVE-2026-84597Medium· 6.5
1w ago

An out-of-bounds read issue was addressed with improved input validation

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclo…

▾ Sunlitapple · ipadosEPSS 0.41%via NVD
CVE-2026-84596Medium· 6.5
1w ago

An out-of-bounds read was addressed with improved bounds checking

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of…

▾ Sunlitapple · ipadosEPSS 0.41%via NVD
CVE-2026-84543High· 7.5PoC
1w ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or…

▾ Midnightapple · macosEPSS 0.43%via NVD
CVE-2026-19086Low· 3.3
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

▾ SunlitIBM · iEPSS 0.12%via NVD
CVE-2026-90815Medium· 6.3PoC
1w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

▾ TwilightRed Hat · FFmpegEPSS 0.42%via NVD
CVE-2026-90994Medium· 4.0
1w ago

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…

▾ SunlitRed Hat · sssdEPSS 0.17%via NVD
CVE-2026-90463Medium· 4.0
1w ago

A flaw was found in the sssd NSS responder

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
CVE-2025-26790Low· 3.7
1w ago

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

▾ SunlitWithSecure · AtlantEPSS 0.33%via NVD
CVE-2026-90698Medium· 5.3PoC
1w ago

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…

▾ TwilightRed Hat · memcachedEPSS 0.86%via NVD
CVE-2026-90716Medium· 5.5PoC
1w ago

A vulnerability was detected in marcobambini Gravity up to 0.9.7

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bou…

▾ Twilightmarcobambini · GravityEPSS 0.36%via NVD
CVE-2026-90681Low· 3.3PoC
1w ago

A weakness has been identified in Matthias-Wandel jhead up to 3.3

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The expl…

▾ TwilightMatthias-Wandel · jheadEPSS 0.16%via NVD
CVE-2026-33968Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.12%via NVD
CVE-2026-33962Low· 2.8
1w ago

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.

▾ SunlitSamsung · Exynos 850 firmwareEPSS 0.13%via NVD
CVE-2026-84445High· 8.7
1w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

▾ Twilightgrpc · grpc-goEPSS 0.64%via NVD
CVE-2026-55209Critical· 9.8
1w ago

resdata is software for reading and writing result files from the Eclipse reservoir simulator

resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRD…

▾ Midnightequinor · resdataEPSS 0.78%via NVD
CVE-2026-54542Low· 3.7
1w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a Tr…

▾ Sunlitnimiq · core-rs-albatrossEPSS 0.44%via NVD
CVE-2026-55093Medium· 6.1PoC
1w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…

▾ Twilightsonos · tractEPSS 0.18%via NVD
CVE-2026-90775Medium· 6.5
2w ago

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out…

▾ SunlitPostGIS · address_standardizerEPSS 0.63%via NVD
CVE-2026-52297Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-52296Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-38332Low· 2.9
2w ago

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

▾ Sunlitcdcseacave · TinyEXIFEPSS 0.15%via NVD
CVE-2026-90560High· 8.2PoC
2w ago

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.62%via NVD
CVE-2026-90557Medium· 6.1
2w ago

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-r…

▾ Sunlitfreeciv · freecivEPSS 0.18%via NVD
CVE-2026-89722Medium· 5.5
2w ago

kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() (CVE-2026-89722)

A flaw was found in the Linux kernel's PCI/sysfs component. A local user with root privileges could trigger an out-of-bounds read in the `pci_write_legacy_io()` function by writing to the `legacy_io` sysfs file with a size less than four b…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89556Medium· 5.5
2w ago

kernel: module: validate string table section types (CVE-2026-89556)

A flaw was found in the Linux kernel. This vulnerability arises from insufficient validation of string table section types within ELF (Executable and Linkable Format) files. A local attacker could exploit this by providing a specially craf…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CWE-125 vulnerabilities (CVEs) — page 5 · VulnSea