Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Unclassified HIGH 8.7
CVE-2026-62292

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-62291

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 au…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-12632

Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire v…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75032

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.8
CVE-2026-23935

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading …

Fix unknown
Fix from $4,000 2026-08-18
Ipados MEDIUM 6.6
CVE-2026-65349

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app m…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.2
CVE-2026-63409

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.2
CVE-2026-65832

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-74238

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote a…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-71980

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.3
CVE-2026-40144

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to versi…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.1
CVE-2026-49282

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs d…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-17649

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-18020

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-17212

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-17226

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-o…

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 6.5
CVE-2026-16878

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 7.5
CVE-2026-16853

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,900 2026-08-13
I MEDIUM 5.3
CVE-2026-16859

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-16861

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.7
CVE-2026-55402

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position c…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73515

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplyin…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.6
CVE-2026-73583

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manage…

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.2
CVE-2026-17485

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-19654

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame …

No fix yet
Fix from $4,900 2026-08-12
Enterprise Linux MEDIUM 6.1
CVE-2026-73434

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc…

No fix yet
Fix from $4,000 2026-08-12
Aws Software Development Kit MEDIUM 5.3
CVE-2026-19643

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t…

No fix yet
Fix from $4,000 2026-08-12
I HIGH 7.7
CVE-2026-16863

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

Fix: after 7.6
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-12232

The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id wi…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.1
CVE-2026-18694

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry …

No fix yet
Fix from $4,900 2026-08-11