← Back to feed Search feed

CWE-125 Out-of-bounds Read vulnerabilities

193 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-89492In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when rCRITICAL9.848%ileNVD2026-09-11
CVE-2026-89494In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler CRITICAL9.852%ileNVD2026-09-11
CVE-2026-89495In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handlerCRITICAL9.852%ileNVD2026-09-11
CVE-2026-89541In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks CRITICAL9.843%ileNVD2026-09-11
CVE-2026-89614In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the free-cluster bitmap scan to the volCRITICAL9.835%ileNVD2026-09-11
CVE-2026-89651In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in hCRITICAL9.849%ileNVD2026-09-11
CVE-2026-55209resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata iCRITICAL9.836%ileNVD2026-09-14
CVE-2026-55211Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fielCRITICAL9.844%ileNVD2026-09-15
CVE-2026-89532In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks CRITICAL9.142%ileNVD2026-09-11
CVE-2026-89650In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info vCRITICAL9.142%ileNVD2026-09-11
CVE-2026-89786In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_diCRITICAL9.151%ileNVD2026-09-16
CVE-2026-90230In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_neCRITICAL9.16%ileNVD2026-09-17
CVE-2026-90414In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was CRITICAL9.18%ileNVD2026-09-17
CVE-2026-68160ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()CRITICAL9.153%ileMicrosoft2026-08-11
CVE-2026-58023Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes pathCRITICAL9.149%ileMicrosoft2026-07-14
CVE-2026-89493In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate rl_used against rl_count in refcounHIGH8.849%ileNVD2026-09-11
CVE-2026-89513In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflowHIGH8.82%ileNVD2026-09-11
CVE-2026-90560zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructHIGH8.827%ileNVD2026-09-12
CVE-2026-52836OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). PriorHIGH8.735%ileNVD2026-09-17
CVE-2026-56978In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This couldHIGH8.40%ileNVD2026-09-15
CVE-2026-56986In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of HIGH8.40%ileNVD2026-09-15
CVE-2026-58699In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This HIGH8.40%ileNVD2026-09-15
CVE-2026-89781In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buHIGH8.48%ileNVD2026-09-16
CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`HIGH8.236%ileMicrosoft2026-06-09
CVE-2026-84516An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH8.136%ileNVD2026-09-14
CVE-2026-89999In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_HIGH8.130%ileNVD2026-09-16
CVE-2026-89947In the Linux kernel, the following vulnerability has been resolved: clk: meson: align gxbb_32k_clk_sel number of parentHIGH8.08%ileNVD2026-09-16
CVE-2026-25282Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.HIGH7.91%ileNVD2026-09-17
CVE-2026-80961In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment HIGH7.86%ileNVD2026-09-11
CVE-2026-80962In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk caHIGH7.86%ileNVD2026-09-11
CVE-2026-92176pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remoHIGH7.87%ileNVD2026-09-15
CVE-2026-89819In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size foHIGH7.86%ileNVD2026-09-16
CVE-2026-93201In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent mHIGH7.84%ileNVD2026-09-17
CVE-2026-89720In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length cHIGH7.78%ileNVD2026-09-11
CVE-2026-89743In the Linux kernel, the following vulnerability has been resolved: misc: nsm: bound the device-reported response lengtHIGH7.74%ileNVD2026-09-11
CVE-2026-65364An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.551%ileNVD2026-09-14
CVE-2026-84543An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, HIGH7.527%ileNVD2026-09-14
CVE-2026-84549An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.546%ileNVD2026-09-14
CVE-2026-85234A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a nHIGH7.538%ileNVD2026-09-15
CVE-2025-11021Libsoup: out-of-bounds read in cookie date handling of libsoup http libraryHIGH7.549%ileMicrosoft2025-09-09
CVE-2025-9230Out-of-bounds read & write in RFC 3211 KEK UnwrapHIGH7.574%ileMicrosoft2025-09-09
CVE-2026-66034libssh2 Heap Out-of-Bounds Read via publickey subsystemHIGH7.534%ileMicrosoft2026-07-14
CVE-2026-57585MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught errorHIGH7.541%ileMicrosoft2026-06-09
CVE-2026-9076Out-of-Bounds Read in CMS Password-Based DecryptionHIGH7.552%ileMicrosoft2026-06-09
CVE-2026-89443In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask iocHIGH7.16%ileNVD2026-09-11
CVE-2026-89731In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AHIGH7.15%ileNVD2026-09-11
CVE-2026-90775PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befoHIGH7.128%ileNVD2026-09-13
CVE-2026-43683An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.15%ileNVD2026-09-14
CVE-2026-43697An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.124%ileNVD2026-09-14
CVE-2026-64736An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS HIGH7.16%ileNVD2026-09-14
CVE-2026-65359An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS HIGH7.14%ileNVD2026-09-14
CVE-2026-84548An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqHIGH7.14%ileNVD2026-09-14
CVE-2026-84565An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.13%ileNVD2026-09-14
CVE-2026-84572An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.13%ileNVD2026-09-14
CVE-2026-91945FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to vHIGH7.146%ileNVD2026-09-15
CVE-2026-91950FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigHIGH7.138%ileNVD2026-09-15
CVE-2026-91956FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function thaHIGH7.128%ileNVD2026-09-15
CVE-2026-91959FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway tHIGH7.128%ileNVD2026-09-15
CVE-2026-76870Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation roHIGH7.124%ileNVD2026-09-15
CVE-2026-89785fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid initHIGH7.111%ileMicrosoft2026-09-08
CVE-2026-89792In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config HIGH7.14%ileNVD2026-09-16
CVE-2026-90016In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmHIGH7.123%ileNVD2026-09-16
CVE-2026-90017In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_framHIGH7.129%ileNVD2026-09-16
CVE-2026-73462On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by HIGH7.116%ileNVD2026-09-16
CVE-2026-92925A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packetHIGH7.127%ileNVD2026-09-17
CVE-2026-90161In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-diHIGH7.110%ileNVD2026-09-17
CVE-2026-90174In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_uHIGH7.19%ileNVD2026-09-17
CVE-2026-90223In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and addHIGH7.117%ileNVD2026-09-17
CVE-2026-90246In the Linux kernel, the following vulnerability has been resolved: apparmor: fix integer overflow in verify_tags() bouHIGH7.110%ileNVD2026-09-17
CVE-2026-90419In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root blHIGH7.112%ileNVD2026-09-17
CVE-2025-38680media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()HIGH7.17%ileMicrosoft2025-09-09
CVE-2026-56136In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attackHIGH7.10%ileMicrosoft2026-08-11
CVE-2026-72568Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message HandlerHIGH7.1Microsoft2026-08-11
CVE-2026-53402fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()HIGH7.13%ileMicrosoft2026-07-14
CVE-2026-53268netfilter: conntrack_irc: fix possible out-of-bounds readHIGH7.133%ileMicrosoft2026-06-09
CVE-2026-22984libceph: prevent potential out-of-bounds reads in handle_auth_done()HIGH7.130%ileMicrosoft2026-01-13
CVE-2026-73863NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/proHIGH7.0NVD2026-09-18
CVE-2026-90557Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processinMEDIUM6.92%ileNVD2026-09-12
CVE-2026-91958FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unboMEDIUM6.910%ileNVD2026-09-15
CVE-2026-93395A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when procMEDIUM6.915%ileNVD2026-09-17
CVE-2026-54633PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed colMEDIUM6.93%ileNVD2026-09-17
CVE-2026-93331A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file MEDIUM6.924%ileNVD2026-09-18
CVE-2026-65365An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.523%ileNVD2026-09-14
CVE-2026-84509An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.524%ileNVD2026-09-14
CVE-2026-84596An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS GoMEDIUM6.534%ileNVD2026-09-14
CVE-2026-84597An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, mMEDIUM6.525%ileNVD2026-09-14
CVE-2026-86900An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. MMEDIUM6.518%ileNVD2026-09-14
CVE-2026-44235rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersMEDIUM6.529%ileNVD2026-09-17
CVE-2026-84451libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unMEDIUM6.5NVD2026-09-18
CVE-2026-53792rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum BlockMEDIUM6.524%ileMicrosoft2026-08-11
CVE-2026-70368Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log messageMEDIUM6.529%ileMicrosoft2026-08-11
CVE-2026-14258Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handlingMEDIUM6.519%ileMicrosoft2026-07-14
CVE-2026-15714Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversiMEDIUM6.552%ileMicrosoft2026-07-14
CVE-2026-55970Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()MEDIUM6.540%ileMicrosoft2026-07-14
CVE-2026-58011Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetimeMEDIUM6.540%ileMicrosoft2026-06-09
CVE-2026-85769Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksizeMEDIUM6.532%ileMicrosoft2026-09-08
CVE-2020-27545libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid lineMEDIUM6.556%ileMicrosoft2023-04-11
CVE-2026-56719MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unautMEDIUM6.332%ileNVD2026-09-16
CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social enMEDIUM6.33%ileNVD2026-09-17
CVE-2026-75032Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folderMEDIUM6.310%ileMicrosoft2026-08-11
CVE-2026-58731In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This MEDIUM6.20%ileNVD2026-09-15
CVE-2026-72522libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same MEDIUM6.29%ileMicrosoft2026-08-11
CVE-2026-55093Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1MEDIUM6.110%ileNVD2026-09-14
CVE-2026-91786A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to valiMEDIUM6.13%ileNVD2026-09-15
CVE-2026-59956OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM6.1NVD2026-09-18
CVE-2025-38713hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()MEDIUM6.16%ileMicrosoft2025-09-09
CVE-2026-75900Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatchMEDIUM6.12%ileMicrosoft2026-08-11
CVE-2026-64450tipc: fix out-of-bounds read in broadcast Gap ACK blocksMEDIUM6.144%ileMicrosoft2026-07-14
CVE-2026-57454Vim: Out-of-bounds Read with Text PropertiesMEDIUM6.17%ileMicrosoft2026-06-09
CVE-2026-18090Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle blockMEDIUM6.16%ileMicrosoft2026-09-08
CVE-2023-1916A flaw was found in tiffcrop a program distributed by the libtiff package. A specially crafted tiff file can lead to an MEDIUM6.130%ileMicrosoft2023-04-11
CVE-2026-73436On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 pMEDIUM6.015%ileNVD2026-09-16
CVE-2025-9232Out-of-bounds read in HTTP client no_proxy handlingMEDIUM5.980%ileMicrosoft2025-09-09
CVE-2026-90698A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_MEDIUM5.542%ileNVD2026-09-14
CVE-2026-28968An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.55%ileNVD2026-09-14
CVE-2026-65376An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM5.54%ileNVD2026-09-14
CVE-2026-65377A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, MEDIUM5.55%ileNVD2026-09-14
CVE-2026-84552The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOMEDIUM5.55%ileNVD2026-09-14
CVE-2026-86903An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS GMEDIUM5.52%ileNVD2026-09-14
CVE-2026-56958In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. ThisMEDIUM5.50%ileNVD2026-09-15
CVE-2026-50291OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.53%ileNVD2026-09-17
CVE-2026-63420OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-63635OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-65969OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-68184cdrom: fix stack out-of-bounds read in CDROMVOLCTRLMEDIUM5.512%ileMicrosoft2026-08-11
CVE-2026-46155smb/client: fix out-of-bounds read in smb2_compound_op()MEDIUM5.540%ileMicrosoft2026-05-12
CVE-2026-46185smb/client: fix out-of-bounds read in symlink_data()MEDIUM5.543%ileMicrosoft2026-05-12
CVE-2026-46190mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()MEDIUM5.53%ileMicrosoft2026-05-12
CVE-2026-64299tracing: Prevent out-of-bounds read in glob matchingMEDIUM5.56%ileMicrosoft2026-07-14
CVE-2026-64487ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parserMEDIUM5.58%ileMicrosoft2026-07-14
CVE-2026-4367Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingMEDIUM5.53%ileMicrosoft2026-06-09
CVE-2026-50262Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributesMEDIUM5.53%ileMicrosoft2026-06-09
CVE-2026-52999netfilter: nfnetlink_osf: fix out-of-bounds read on option matchingMEDIUM5.546%ileMicrosoft2026-06-09
CVE-2026-57452Vim: Out-of-bounds Read with libsodium-encrypted FilesMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-84532An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.422%ileNVD2026-09-14
CVE-2026-92255Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by impMEDIUM5.319%ileNVD2026-09-15
CVE-2026-16768Gdk-pixbuf: out-of-bounds read in ico parserMEDIUM5.315%ileMicrosoft2026-07-14
CVE-2026-12969Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validationMEDIUM5.334%ileMicrosoft2026-06-09
CVE-2026-57451Vim: Out-of-bounds Read in Text Property CountMEDIUM5.36%ileMicrosoft2026-06-09
CVE-2026-2443Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosureMEDIUM5.338%ileMicrosoft2026-02-10
CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processingMEDIUM5.31%ileMicrosoft2026-09-08
CVE-2026-2243Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsingMEDIUM5.12%ileMicrosoft2026-02-10
CVE-2026-78546Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: befMEDIUM4.84%ileNVD2026-09-11
CVE-2026-0716Libsoup: out-of-bounds read in libsoup websocket frame processingMEDIUM4.830%ileMicrosoft2026-01-13
CVE-2026-91726Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memoMEDIUM4.719%ileNVD2026-09-15
CVE-2026-76151Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt GrMEDIUM4.649%ileNVD2026-09-16
CVE-2026-89726lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()MEDIUM4.48%ileMicrosoft2026-09-08
CVE-2026-0177In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This couMEDIUM4.40%ileNVD2026-09-15
CVE-2026-74689net/atm: fix slab-out-of-bounds read in vcc_setsockopt()MEDIUM4.44%ileMicrosoft2026-08-11
CVE-2026-84524An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS MEDIUM4.336%ileNVD2026-09-14
CVE-2026-16514gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS MEDIUM4.3NVD2026-09-18
CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length boundMEDIUM4.326%ileMicrosoft2026-09-08
CVE-2026-80772HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()MEDIUM4.37%ileMicrosoft2026-09-08
CVE-2026-33957An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory froMEDIUM4.21%ileNVD2026-09-14
CVE-2026-90463A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specMEDIUM4.01%ileNVD2026-09-14
CVE-2026-90994A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser,MEDIUM4.02%ileNVD2026-09-14
CVE-2026-84448libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inliMEDIUM4.0NVD2026-09-18
CVE-2026-47104libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()MEDIUM4.03%ileMicrosoft2026-05-12
CVE-2025-26790Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memoLOW3.727%ileNVD2026-09-14
CVE-2026-54542Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior toLOW3.720%ileNVD2026-09-14
CVE-2026-84449libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() LOW3.7NVD2026-09-18
CVE-2026-89156PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF daLOW3.714%ileMicrosoft2026-09-08
CVE-2026-89160PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF suLOW3.712%ileMicrosoft2026-09-08
CVE-2026-74671ima: fix out-of-bounds read in xattr_verify()LOW3.48%ileMicrosoft2026-08-11
CVE-2026-19086IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authLOW3.32%ileNVD2026-09-14
CVE-2026-80598ntfs3: fix out-of-bounds read in decompress_lzntLOW3.33%ileMicrosoft2026-08-11
CVE-2026-16512gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switchedLOW3.1NVD2026-09-18
CVE-2026-38332TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectAreLOW2.92%ileNVD2026-09-13
CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libLOW2.95%ileNVD2026-09-13
CVE-2026-52297FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in LOW2.92%ileNVD2026-09-13
CVE-2026-86137In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro iLOW2.93%ileMicrosoft2026-09-08
CVE-2026-33962An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. ALOW2.81%ileNVD2026-09-14
CVE-2026-33968An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680.LOW2.81%ileNVD2026-09-14
CVE-2026-74567keys: fix out-of-bounds read in keyring_get_key_chunk()LOW2.52%ileMicrosoft2026-08-11
CVE-2026-54579mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validaLOW2.34%ileNVD2026-09-17
CVE-2026-90815A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setLOW2.116%ileNVD2026-09-14
CVE-2026-90716A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of tLOW2.019%ileNVD2026-09-14
CVE-2026-90681A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c oLOW1.92%ileNVD2026-09-14
CVE-2026-92475A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utLOW1.94%ileNVD2026-09-16
CVE-2026-90826A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrapLOW0.95%ileNVD2026-09-14
CVE-2026-89629In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Check size of status and firmwarUNKNOWN10%ileNVD2026-09-11
CVE-2026-89722In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_legaUNKNOWN10%ileNVD2026-09-11
CVE-2026-89730In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trailUNKNOWN12%ileNVD2026-09-11
CVE-2026-92240A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagUNKNOWN12%ileNVD2026-09-15
CVE-2026-90416In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_paramUNKNOWN12%ileNVD2026-09-17
CVE-2026-93055In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlUNKNOWN8%ileNVD2026-09-17
CVE-2026-93120In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qwUNKNOWN12%ileNVD2026-09-17
CVE-2026-73638Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_UNKNOWN8%ileNVD2026-09-17
CVE-2026-19028HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readUNKNOWN2%ileMicrosoft2026-08-11
CVE-2026-55894Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecodeUNKNOWN3%ileMicrosoft2026-08-11
CVE-2026-63383Libevent: decode_tag_internal() can lead to out-of-bounds readUNKNOWN32%ileMicrosoft2026-08-11
CVE-2026-7258Out-of-bounds read in urldecode() on NetBSDUNKNOWN27%ileMicrosoft2026-05-12
CVE-2026-52859Vim: Out-of-bounds Read in Terminal Screen SnapshotUNKNOWN23%ileMicrosoft2026-06-09