VulnSea

CWE-126

CVEs classified under CWE-126, newest first.

89 CVEsRSS

CVE-2026-58013Medium· 6.5
2mo ago

A flaw was found in GLib

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This…

▾ Sunlitgnome · glibEPSS 0.85%via NVD
CVE-2026-58012Medium· 6.5
2mo ago

A flaw was found in GLib

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings usin…

▾ Sunlitgnome · glibEPSS 0.85%via NVD
CVE-2026-58010Medium· 6.5
2mo ago

A flaw was found in GLib

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bou…

▾ Sunlitgnome · glibEPSS 0.85%via NVD
CVE-2026-41992High· 7.5⚖ disputed
3mo ago

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array …

▾ Twilightgnu · gzipEPSS 0.56%via NVD
CVE-2026-49854Low· 3.7
3mo ago

Tornado has out-of-bounds memory access via C extension

Tornado has out-of-bounds memory access via C extension

▾ Sunlittornado · tornadoEPSS 0.42%via OSV
CVE-2026-45460Medium· 4.7
3mo ago

Microsoft Office Information Disclosure Vulnerability

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.42%via CVEORG
CVE-2026-42828High· 7.8
3mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-44185High· 7.3
3mo ago

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

▾ Twilightapache · http_serverEPSS 1.8%via NVD
CVE-2026-5260High· 8.2
4mo ago

A flaw was found in libgnutls

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corrupti…

▾ TwilightRed Hat · gnutlsEPSS 0.95%via NVD
CVE-2026-41898Medium· 5.3
5mo ago

rust-openssl provides OpenSSL bindings for the Rust programming language

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_sta…

▾ Sunlitrust-openssl_project · rust-opensslEPSS 0.45%via NVD
CVE-2026-26155Medium· 6.5
5mo ago

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.00%via CVEORG
CVE-2026-26169Medium· 6.1
5mo ago

Windows Kernel Memory Information Disclosure Vulnerability

Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-26184High· 7.8
5mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-2394Medium· 6.5
5mo ago

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 befo…

▾ Sunlitrti · connext_professionalEPSS 0.16%via NVD
CVE-2026-24028Medium· 5.3
6mo ago

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of…

▾ Sunlitpowerdns · dnsdistEPSS 1.0%via NVD
CVE-2026-3203Medium· 5.5
7mo ago

Buffer Over-read in Wireshark

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.26%via CVEORG
CVE-2026-25646High· 8.1
7mo ago

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API functio…

▾ Twilightlibpng · libpngEPSS 0.64%via NVD
CVE-2025-12106Critical· 9.1
10mo ago

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

▾ Midnightopenvpn · openvpnEPSS 0.56%via NVD
CVE-2025-27036Medium· 6.1
1y ago

Information disclosure when Video engine escape input data is less than expected minimum size.

Information disclosure when Video engine escape input data is less than expected minimum size.

▾ Sunlitqualcomm · fastconnect_6700_firmwareEPSS 0.08%via NVD
CVE-2025-27033Medium· 6.1
1y ago

Information disclosure while running video usecase having rogue firmware.

Information disclosure while running video usecase having rogue firmware.

▾ Sunlitqualcomm · qcm5430_firmwareEPSS 0.08%via NVD
CVE-2025-27030Medium· 6.1
1y ago

information disclosure while invoking calibration data from user space to update firmware size.

information disclosure while invoking calibration data from user space to update firmware size.

▾ Sunlitqualcomm · c-v2x_9150_firmwareEPSS 0.08%via NVD
CVE-2025-21488High· 8.2
1y ago

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

▾ Twilightqualcomm · fastconnect_6200_firmwareEPSS 0.27%via NVD
CVE-2025-21487High· 8.2
1y ago

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

▾ Twilightqualcomm · apq8017_firmwareEPSS 0.26%via NVD
CVE-2025-21484High· 8.2
1y ago

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

▾ Twilightqualcomm · sm8750_firmwareEPSS 0.26%via NVD
CVE-2025-4582High· 7.1⚖ disputed
1y ago

Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers

Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6…

▾ Twilightrti · connext_professionalEPSS 0.14%via NVD
CVE-2023-53159Medium· 4.5
1y ago

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

▾ Sunlitsfackler · opensslEPSS 0.19%via NVD
CVE-2025-32052Medium· 6.5
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.

▾ SunlitEPSS 0.65%via NVD
CVE-2025-32053Medium· 6.5
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.

▾ SunlitEPSS 0.65%via NVD
CVE-2024-30069Medium· 4.7
2y ago

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Windows Remote Access Connection Manager Information Disclosure Vulnerability

▾ Sunlitmicrosoft · windows_10_1507EPSS 0.57%via NVD
CWE-126 vulnerabilities (CVEs) — page 3 · VulnSea