Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Freerdp CRITICAL 9.1
CVE-2026-57158

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incompl…

Fix: 3.28.0+
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.1
CVE-2026-14461

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups …

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40454

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-11404

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-co…

Patch available
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-58304

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 7…

Patch available
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-58307

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue a…

Patch available
Fix from $1,600 2026-07-09
Chrome HIGH 8.8
CVE-2026-15114

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
U Boot MEDIUM 5.3
CVE-2026-29007

U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowi…

Fix: 2026.04+
Fix from $1,600 2026-07-08
Imagemagick HIGH 7.1
CVE-2026-56374

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format…

Fix: 7.1.2-19+
Fix from $1,950 2026-07-08
Imagemagick HIGH 8.1
CVE-2026-56362

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metad…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57258

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements …

Fix: after 2026.1.1.70276
Fix from $1,600 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57253

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is…

Fix: after 2026.1.1.36485
Fix from $1,600 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57255

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's…

Fix: after 2026.1.1.36485
Fix from $1,600 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57257

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity a…

Fix: after 2026.1.1.70276
Fix from $1,600 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57241

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the applicati…

Fix: after 2026.1.1.36485
Fix from $1,600 2026-07-08
Pdf Editor MEDIUM 6.1
CVE-2026-57243

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdat…

Fix: after 2026.1.1.36485
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-50811

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttg…

Patch available
Fix from $1,600 2026-07-07
Dbi CRITICAL 9.1
CVE-2026-14740

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL …

Fix: 1.650+
Fix from $2,300 2026-07-07
Wget HIGH 7.5
CVE-2026-58469

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/m…

Fix: after 1.25.0
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-13705

Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb…

Patch available
Fix from $1,950 2026-07-06
Zephyr MEDIUM 5.3
CVE-2026-10657

Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".…

Fix: after 4.4.0
Fix from $1,600 2026-07-05
Linux Kernel HIGH 8.8
CVE-2026-53360

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB sp…

Fix: 6.12.93 / 6.18.35+
Fix from $1,950 2026-07-04
Unclassified CRITICAL 9.1
CVE-2026-56015

Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the tr…

Patch available
Fix from $2,300 2026-07-03
Arduplane CRITICAL 9.1
CVE-2026-38971

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle…

Fix: after 4.6.3
Fix from $2,300 2026-07-02
Chrome CRITICAL 9.6
CVE-2026-14416

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT…

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome CRITICAL 9.6
CVE-2026-14420

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a …

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome HIGH 8.8
CVE-2026-14422

Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory ac…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome MEDIUM 5.9
CVE-2026-14406

Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain …

Fix: 150.0.7871.46+
Fix from $1,600 2026-07-01
Chrome MEDIUM 6.5
CVE-2026-14396

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chr…

Fix: 150.0.7871.46+
Fix from $1,600 2026-07-01
Chrome MEDIUM 6.5
CVE-2026-14386

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 150.0.7871.46+
Fix from $1,600 2026-07-01