Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Unclassified HIGH 8.1
CVE-2026-8796

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and…

Patch available
Fix from $1,950 2026-05-31
Zephyr HIGH 7.8
CVE-2026-5071

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in …

Fix: after 4.3.0
Fix from $1,950 2026-05-30
Liboqs MEDIUM 5.3
CVE-2026-46344

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds…

Fix: after 0.15.0
Fix from $1,600 2026-05-29
Liboqs MEDIUM 5.3
CVE-2026-44518

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds…

Fix: after 0.15.0
Fix from $1,600 2026-05-29
Unclassified HIGH 8.2
CVE-2026-45615

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated …

Mitigation only
Fix from $1,950 2026-05-29
Wf 500 Firmware HIGH 7.8
CVE-2025-41278

Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with …

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Chrome MEDIUM 6.5
CVE-2026-9996

Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information fr…

Fix: 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome HIGH 8.3
CVE-2026-9975

Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome MEDIUM 6.5
CVE-2026-9953

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from proce…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome HIGH 8.8
CVE-2026-9928

Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTM…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9910

Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox vi…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome MEDIUM 6.5
CVE-2026-9908

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from proce…

Fix: 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome HIGH 8.3
CVE-2026-9895

Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9889

Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox e…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9875

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome HIGH 8.3
CVE-2026-10017

Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenti…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-39929

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30…

Mitigation only
Fix from $1,950 2026-05-28
Ubuntu Linux HIGH 7.8
CVE-2026-47333

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a …

Patch available
Fix from $1,950 2026-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2026-47332

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-boun…

Patch available
Fix from $1,600 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46230

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg Check bounds against th…

Fix: 5.15.209 / 6.1.175+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46204

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to us…

Fix: 6.6.140 / 6.12.90+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46199

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg Check bounds against th…

Fix: 6.1.175 / 6.6.140+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46203

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the control…

Fix: 7.0.9+
Fix from $1,950 2026-05-28
Linux Kernel CRITICAL 9.1
CVE-2026-46185

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message()…

Fix: 6.1.175 / 6.6.140+
Fix from $2,300 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46190

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() Sashiko …

Fix: 6.6.140 / 6.12.88+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46191

In the Linux kernel, the following vulnerability has been resolved: fbcon: Avoid OOB font access if console rotation fails Clear the font buffer if…

Fix: 6.6.140 / 6.12.90+
Fix from $1,950 2026-05-28
Linux Kernel CRITICAL 9.1
CVE-2026-46155

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a tr…

Fix: 6.6.140 / 6.12.88+
Fix from $2,300 2026-05-28
Linux Kernel HIGH 8.1
CVE-2026-46138

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_comple…

Fix: 6.5 / 6.6.140+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46140

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_…

Fix: 6.7 / 6.12.88+
Fix from $1,950 2026-05-28
Linux Kernel HIGH 7.1
CVE-2026-46130

In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode…

Fix: 6.2 / 6.7+
Fix from $1,950 2026-05-28