108 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2022-4337 | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. | CRITICAL | 9.8 | 68%ile | Microsoft | 2023-01-10 |
| CVE-2026-17701 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote atta | CRITICAL | 9.6 | 28%ile | NVD | 2026-07-30 |
| CVE-2026-17801 | Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-30 |
| CVE-2024-25178 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler i | CRITICAL | 9.4 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2024-32622 | HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_ex | CRITICAL | 9.1 | 59%ile | Microsoft | 2024-05-14 |
| CVE-2026-17678 | Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re | HIGH | 8.8 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17971 | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p | HIGH | 8.8 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-66360 | The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis | HIGH | 8.7 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-67290 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG | HIGH | 8.7 | 36%ile | NVD | 2026-08-01 |
| CVE-2026-67291 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments | HIGH | 8.7 | 26%ile | NVD | 2026-08-01 |
| CVE-2026-67301 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an | HIGH | 8.7 | 26%ile | NVD | 2026-08-01 |
| CVE-2026-62959 | Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started w | HIGH | 8.2 | 31%ile | NVD | 2026-07-31 |
| CVE-2026-57235 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | HIGH | 8.2 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-17869 | Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bound | HIGH | 8.1 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-17995 | Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds | HIGH | 8.1 | 15%ile | NVD | 2026-07-30 |
| CVE-2023-0049 | Out-of-bounds Read in vim/vim | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2026-41703 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr | HIGH | 7.6 | 43%ile | NVD | 2026-07-30 |
| CVE-2026-20479 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv | HIGH | 7.5 | 40%ile | NVD | 2026-08-03 |
| CVE-2026-66034 | libssh2 Heap Out-of-Bounds Read via publickey subsystem | HIGH | 7.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-40890 | github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer | HIGH | 7.5 | 27%ile | Microsoft | 2026-04-14 |
| CVE-2025-11021 | Libsoup: out-of-bounds read in cookie date handling of libsoup http library | HIGH | 7.5 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 76%ile | Microsoft | 2025-09-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-63550 | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess | HIGH | 7.1 | 16%ile | NVD | 2026-07-30 |
| CVE-2026-65421 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-66364 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-66369 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer- | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-66720 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-69244 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r | HIGH | 7.1 | 22%ile | NVD | 2026-08-03 |
| CVE-2026-53402 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53390 | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() | HIGH | 7.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2025-38680 | media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2026-53268 | netfilter: conntrack_irc: fix possible out-of-bounds read | HIGH | 7.1 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2025-38111 | net/mdiobus: Fix potential out-of-bounds read/write access | HIGH | 7.1 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-38249 | ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2026-10848 | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j | HIGH | 7.0 | 10%ile | NVD | 2026-08-02 |
| CVE-2025-38204 | jfs: fix array-index-out-of-bounds read in add_missing_indices | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2026-56758 | The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain | MEDIUM | 6.9 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-61893 | A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu | MEDIUM | 6.9 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-63033 | A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO | MEDIUM | 6.9 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-66349 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed | MEDIUM | 6.9 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-16530 | A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t | MEDIUM | 6.5 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-70368 | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m | MEDIUM | 6.5 | — | NVD | 2026-08-04 |
| CVE-2026-14258 | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling | MEDIUM | 6.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-15714 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversi | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2025-4969 | Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c | MEDIUM | 6.5 | 52%ile | Microsoft | 2025-05-13 |
| CVE-2023-6174 | Out-of-bounds Read in Wireshark | MEDIUM | 6.5 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2026-58160 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0 | MEDIUM | 6.3 | 43%ile | NVD | 2026-07-29 |
| CVE-2026-50735 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me | MEDIUM | 6.1 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-16465 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili | MEDIUM | 6.1 | 4%ile | NVD | 2026-07-29 |
| CVE-2026-64450 | tipc: fix out-of-bounds read in broadcast Gap ACK blocks | MEDIUM | 6.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2025-38713 | hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() | MEDIUM | 6.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-12996 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten | MEDIUM | 6.0 | 32%ile | NVD | 2026-07-30 |
| CVE-2026-35201 | Discount has an Out-of-bounds Read in rdiscount | MEDIUM | 5.9 | 20%ile | Microsoft | 2026-04-14 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2026-17745 | Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the ren | MEDIUM | 5.8 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17770 | Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-67550 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex again | MEDIUM | 5.7 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17550 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili | MEDIUM | 5.5 | 4%ile | NVD | 2026-07-29 |
| CVE-2026-20494 | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc | MEDIUM | 5.5 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-18583 | A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc | MEDIUM | 5.5 | 40%ile | NVD | 2026-08-03 |
| CVE-2026-68742 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen | MEDIUM | 5.5 | 4%ile | NVD | 2026-08-03 |
| CVE-2026-64299 | tracing: Prevent out-of-bounds read in glob matching | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64487 | ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-39855 | osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-39856 | osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-46155 | smb/client: fix out-of-bounds read in smb2_compound_op() | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-46190 | mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46185 | smb/client: fix out-of-bounds read in symlink_data() | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-50262 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-57452 | Vim: Out-of-bounds Read with libsodium-encrypted Files | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-4367 | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2025-38320 | arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2022-48303 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum | MEDIUM | 5.5 | 91%ile | Microsoft | 2023-01-10 |
| CVE-2023-23454 | cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (sla | MEDIUM | 5.5 | 24%ile | Microsoft | 2023-01-10 |
| CVE-2024-31584 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader. | MEDIUM | 5.5 | 31%ile | Microsoft | 2024-04-09 |
| USN-8620-4 | USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities | MEDIUM | 5.5 | — | Ubuntu | 2026-07-31 |
| USN-8620-3 | USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities | MEDIUM | 5.5 | — | Ubuntu | 2026-07-31 |
| USN-8620-2 | USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities | MEDIUM | 5.5 | — | Ubuntu | 2026-07-29 |
| CVE-2026-10773 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c | MEDIUM | 5.4 | 7%ile | NVD | 2026-08-01 |
| CVE-2023-51592 | BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2023-51580 | BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2023-51589 | BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2026-64685 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1. | MEDIUM | 5.3 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-58216 | An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi | MEDIUM | 5.3 | 41%ile | NVD | 2026-07-30 |
| CVE-2026-55777 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b | MEDIUM | 5.3 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-67306 | FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu | MEDIUM | 5.3 | 20%ile | NVD | 2026-08-01 |
| CVE-2026-16768 | Gdk-pixbuf: out-of-bounds read in ico parser | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-12969 | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-57451 | Vim: Out-of-bounds Read in Text Property Count | MEDIUM | 5.3 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-13379 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat | MEDIUM | 5.1 | 21%ile | NVD | 2026-07-30 |
| CVE-2023-53159 | The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho | MEDIUM | 4.5 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2026-20488 | In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati | MEDIUM | 4.4 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20489 | In display, there is a possible information disclosure due to an integer overflow. This could lead to local information | MEDIUM | 4.4 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20490 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic | MEDIUM | 4.4 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20496 | In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information | MEDIUM | 4.4 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-40026 | Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-40025 | Sleuth Kit APFS Keybag Parser Out-of-Bounds Read | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-17772 | Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bound | MEDIUM | 4.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-41079 | OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users | MEDIUM | 4.3 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-47104 | libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array() | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-10684 | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu | LOW | 3.0 | 1%ile | NVD | 2026-07-29 |
| CVE-2026-66401 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail | LOW | 2.4 | 5%ile | NVD | 2026-08-01 |
| CVE-2026-39979 | jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers | UNKNOWN | — | 43%ile | Microsoft | 2026-04-14 |
| CVE-2026-41677 | rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-52859 | Vim: Out-of-bounds Read in Terminal Screen Snapshot | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |