193 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-89492 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when r | CRITICAL | 9.8 | 48%ile | NVD | 2026-09-11 |
| CVE-2026-89494 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-11 |
| CVE-2026-89495 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-11 |
| CVE-2026-89541 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks | CRITICAL | 9.8 | 43%ile | NVD | 2026-09-11 |
| CVE-2026-89614 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the free-cluster bitmap scan to the vol | CRITICAL | 9.8 | 35%ile | NVD | 2026-09-11 |
| CVE-2026-89651 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in h | CRITICAL | 9.8 | 49%ile | NVD | 2026-09-11 |
| CVE-2026-55209 | resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata i | CRITICAL | 9.8 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-55211 | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fiel | CRITICAL | 9.8 | 44%ile | NVD | 2026-09-15 |
| CVE-2026-89532 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks | CRITICAL | 9.1 | 42%ile | NVD | 2026-09-11 |
| CVE-2026-89650 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v | CRITICAL | 9.1 | 42%ile | NVD | 2026-09-11 |
| CVE-2026-89786 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_di | CRITICAL | 9.1 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-90230 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_ne | CRITICAL | 9.1 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-90414 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was | CRITICAL | 9.1 | 8%ile | NVD | 2026-09-17 |
| CVE-2026-68160 | ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() | CRITICAL | 9.1 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-58023 | Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path | CRITICAL | 9.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-89493 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate rl_used against rl_count in refcoun | HIGH | 8.8 | 49%ile | NVD | 2026-09-11 |
| CVE-2026-89513 | In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflow | HIGH | 8.8 | 2%ile | NVD | 2026-09-11 |
| CVE-2026-90560 | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress construct | HIGH | 8.8 | 27%ile | NVD | 2026-09-12 |
| CVE-2026-52836 | OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior | HIGH | 8.7 | 35%ile | NVD | 2026-09-17 |
| CVE-2026-56978 | In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could | HIGH | 8.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56986 | In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of | HIGH | 8.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-58699 | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This | HIGH | 8.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-89781 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu | HIGH | 8.4 | 8%ile | NVD | 2026-09-16 |
| CVE-2026-57235 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | HIGH | 8.2 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-84516 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 8.1 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-89999 | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_ | HIGH | 8.1 | 30%ile | NVD | 2026-09-16 |
| CVE-2026-89947 | In the Linux kernel, the following vulnerability has been resolved: clk: meson: align gxbb_32k_clk_sel number of parent | HIGH | 8.0 | 8%ile | NVD | 2026-09-16 |
| CVE-2026-25282 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | HIGH | 7.9 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-80961 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment | HIGH | 7.8 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-80962 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk ca | HIGH | 7.8 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-92176 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo | HIGH | 7.8 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-89819 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size fo | HIGH | 7.8 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-93201 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent m | HIGH | 7.8 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-89720 | In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length c | HIGH | 7.7 | 8%ile | NVD | 2026-09-11 |
| CVE-2026-89743 | In the Linux kernel, the following vulnerability has been resolved: misc: nsm: bound the device-reported response lengt | HIGH | 7.7 | 4%ile | NVD | 2026-09-11 |
| CVE-2026-65364 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.5 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-84543 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, | HIGH | 7.5 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-84549 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.5 | 46%ile | NVD | 2026-09-14 |
| CVE-2026-85234 | A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a n | HIGH | 7.5 | 38%ile | NVD | 2026-09-15 |
| CVE-2025-11021 | Libsoup: out-of-bounds read in cookie date handling of libsoup http library | HIGH | 7.5 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 74%ile | Microsoft | 2025-09-09 |
| CVE-2026-66034 | libssh2 Heap Out-of-Bounds Read via publickey subsystem | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-57585 | MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error | HIGH | 7.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-89443 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioc | HIGH | 7.1 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-89731 | In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds A | HIGH | 7.1 | 5%ile | NVD | 2026-09-11 |
| CVE-2026-90775 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befo | HIGH | 7.1 | 28%ile | NVD | 2026-09-13 |
| CVE-2026-43683 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-43697 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-64736 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS | HIGH | 7.1 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-65359 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | HIGH | 7.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84548 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 7.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84565 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-84572 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-91945 | FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to v | HIGH | 7.1 | 46%ile | NVD | 2026-09-15 |
| CVE-2026-91950 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsig | HIGH | 7.1 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-91956 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha | HIGH | 7.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-91959 | FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t | HIGH | 7.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-76870 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation ro | HIGH | 7.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-89785 | fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init | HIGH | 7.1 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89792 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config | HIGH | 7.1 | 4%ile | NVD | 2026-09-16 |
| CVE-2026-90016 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wm | HIGH | 7.1 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-90017 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_fram | HIGH | 7.1 | 29%ile | NVD | 2026-09-16 |
| CVE-2026-73462 | On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by | HIGH | 7.1 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-92925 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packet | HIGH | 7.1 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-90161 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-di | HIGH | 7.1 | 10%ile | NVD | 2026-09-17 |
| CVE-2026-90174 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_u | HIGH | 7.1 | 9%ile | NVD | 2026-09-17 |
| CVE-2026-90223 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and add | HIGH | 7.1 | 17%ile | NVD | 2026-09-17 |
| CVE-2026-90246 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix integer overflow in verify_tags() bou | HIGH | 7.1 | 10%ile | NVD | 2026-09-17 |
| CVE-2026-90419 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root bl | HIGH | 7.1 | 12%ile | NVD | 2026-09-17 |
| CVE-2025-38680 | media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() | HIGH | 7.1 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2026-56136 | In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attack | HIGH | 7.1 | 0%ile | Microsoft | 2026-08-11 |
| CVE-2026-72568 | Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler | HIGH | 7.1 | — | Microsoft | 2026-08-11 |
| CVE-2026-53402 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53268 | netfilter: conntrack_irc: fix possible out-of-bounds read | HIGH | 7.1 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-22984 | libceph: prevent potential out-of-bounds reads in handle_auth_done() | HIGH | 7.1 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-73863 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro | HIGH | 7.0 | — | NVD | 2026-09-18 |
| CVE-2026-90557 | Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processin | MEDIUM | 6.9 | 2%ile | NVD | 2026-09-12 |
| CVE-2026-91958 | FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo | MEDIUM | 6.9 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-93395 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc | MEDIUM | 6.9 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-54633 | PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col | MEDIUM | 6.9 | 3%ile | NVD | 2026-09-17 |
| CVE-2026-93331 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file | MEDIUM | 6.9 | 24%ile | NVD | 2026-09-18 |
| CVE-2026-65365 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-84509 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-84596 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Go | MEDIUM | 6.5 | 34%ile | NVD | 2026-09-14 |
| CVE-2026-84597 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, m | MEDIUM | 6.5 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-86900 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. M | MEDIUM | 6.5 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-44235 | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders | MEDIUM | 6.5 | 29%ile | NVD | 2026-09-17 |
| CVE-2026-84451 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of un | MEDIUM | 6.5 | — | NVD | 2026-09-18 |
| CVE-2026-53792 | rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70368 | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message | MEDIUM | 6.5 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-14258 | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling | MEDIUM | 6.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15714 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversi | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-55970 | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58011 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-85769 | Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2020-27545 | libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line | MEDIUM | 6.5 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2026-56719 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unaut | MEDIUM | 6.3 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-93376 | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social en | MEDIUM | 6.3 | 3%ile | NVD | 2026-09-17 |
| CVE-2026-75032 | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder | MEDIUM | 6.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-58731 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This | MEDIUM | 6.2 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-72522 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same | MEDIUM | 6.2 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-55093 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1 | MEDIUM | 6.1 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-91786 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to vali | MEDIUM | 6.1 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-59956 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2025-38713 | hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() | MEDIUM | 6.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2026-75900 | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64450 | tipc: fix out-of-bounds read in broadcast Gap ACK blocks | MEDIUM | 6.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-18090 | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2023-1916 | A flaw was found in tiffcrop a program distributed by the libtiff package. A specially crafted tiff file can lead to an | MEDIUM | 6.1 | 30%ile | Microsoft | 2023-04-11 |
| CVE-2026-73436 | On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 p | MEDIUM | 6.0 | 15%ile | NVD | 2026-09-16 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 80%ile | Microsoft | 2025-09-09 |
| CVE-2026-90698 | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_ | MEDIUM | 5.5 | 42%ile | NVD | 2026-09-14 |
| CVE-2026-28968 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-65376 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 5.5 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-65377 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84552 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-86903 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS G | MEDIUM | 5.5 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-56958 | In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This | MEDIUM | 5.5 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-50291 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | 3%ile | NVD | 2026-09-17 |
| CVE-2026-63420 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | NVD | 2026-09-18 |
| CVE-2026-63635 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | NVD | 2026-09-18 |
| CVE-2026-65969 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | NVD | 2026-09-18 |
| CVE-2026-68184 | cdrom: fix stack out-of-bounds read in CDROMVOLCTRL | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-46155 | smb/client: fix out-of-bounds read in smb2_compound_op() | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46185 | smb/client: fix out-of-bounds read in symlink_data() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-46190 | mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-64299 | tracing: Prevent out-of-bounds read in glob matching | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64487 | ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-4367 | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50262 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52999 | netfilter: nfnetlink_osf: fix out-of-bounds read on option matching | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-57452 | Vim: Out-of-bounds Read with libsodium-encrypted Files | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-84532 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.4 | 22%ile | NVD | 2026-09-14 |
| CVE-2026-92255 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by imp | MEDIUM | 5.3 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-16768 | Gdk-pixbuf: out-of-bounds read in ico parser | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-12969 | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-57451 | Vim: Out-of-bounds Read in Text Property Count | MEDIUM | 5.3 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-2443 | Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-02-10 |
| CVE-2026-71222 | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing | MEDIUM | 5.3 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-2243 | Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing | MEDIUM | 5.1 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-78546 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: bef | MEDIUM | 4.8 | 4%ile | NVD | 2026-09-11 |
| CVE-2026-0716 | Libsoup: out-of-bounds read in libsoup websocket frame processing | MEDIUM | 4.8 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-91726 | Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memo | MEDIUM | 4.7 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-76151 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Gr | MEDIUM | 4.6 | 49%ile | NVD | 2026-09-16 |
| CVE-2026-89726 | lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-0177 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This cou | MEDIUM | 4.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-74689 | net/atm: fix slab-out-of-bounds read in vcc_setsockopt() | MEDIUM | 4.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-84524 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 4.3 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-16514 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS | MEDIUM | 4.3 | — | NVD | 2026-09-18 |
| CVE-2026-87875 | Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound | MEDIUM | 4.3 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-80772 | HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() | MEDIUM | 4.3 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-33957 | An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory fro | MEDIUM | 4.2 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-90463 | A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec | MEDIUM | 4.0 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-90994 | A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, | MEDIUM | 4.0 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-84448 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inli | MEDIUM | 4.0 | — | NVD | 2026-09-18 |
| CVE-2026-47104 | libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array() | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-26790 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo | LOW | 3.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-54542 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to | LOW | 3.7 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-84449 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() | LOW | 3.7 | — | NVD | 2026-09-18 |
| CVE-2026-89156 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF da | LOW | 3.7 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-89160 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF su | LOW | 3.7 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-74671 | ima: fix out-of-bounds read in xattr_verify() | LOW | 3.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-19086 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth | LOW | 3.3 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-80598 | ntfs3: fix out-of-bounds read in decompress_lznt | LOW | 3.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-16512 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched | LOW | 3.1 | — | NVD | 2026-09-18 |
| CVE-2026-38332 | TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectAre | LOW | 2.9 | 2%ile | NVD | 2026-09-13 |
| CVE-2026-52296 | FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in lib | LOW | 2.9 | 5%ile | NVD | 2026-09-13 |
| CVE-2026-52297 | FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in | LOW | 2.9 | 2%ile | NVD | 2026-09-13 |
| CVE-2026-86137 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro i | LOW | 2.9 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-33962 | An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A | LOW | 2.8 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-33968 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. | LOW | 2.8 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-74567 | keys: fix out-of-bounds read in keyring_get_key_chunk() | LOW | 2.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-54579 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without valida | LOW | 2.3 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-90815 | A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function set | LOW | 2.1 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-90716 | A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of t | LOW | 2.0 | 19%ile | NVD | 2026-09-14 |
| CVE-2026-90681 | A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c o | LOW | 1.9 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-92475 | A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/ut | LOW | 1.9 | 4%ile | NVD | 2026-09-16 |
| CVE-2026-90826 | A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrap | LOW | 0.9 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-89629 | In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Check size of status and firmwar | UNKNOWN | — | 10%ile | NVD | 2026-09-11 |
| CVE-2026-89722 | In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_lega | UNKNOWN | — | 10%ile | NVD | 2026-09-11 |
| CVE-2026-89730 | In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trail | UNKNOWN | — | 12%ile | NVD | 2026-09-11 |
| CVE-2026-92240 | A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untag | UNKNOWN | — | 12%ile | NVD | 2026-09-15 |
| CVE-2026-90416 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_param | UNKNOWN | — | 12%ile | NVD | 2026-09-17 |
| CVE-2026-93055 | In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_syml | UNKNOWN | — | 8%ile | NVD | 2026-09-17 |
| CVE-2026-93120 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw | UNKNOWN | — | 12%ile | NVD | 2026-09-17 |
| CVE-2026-73638 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ | UNKNOWN | — | 8%ile | NVD | 2026-09-17 |
| CVE-2026-19028 | HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-55894 | Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-63383 | Libevent: decode_tag_internal() can lead to out-of-bounds read | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-52859 | Vim: Out-of-bounds Read in Terminal Screen Snapshot | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |