Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 8.7 CVE-2026-62292 libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-62291 libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 au… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-12632 Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire v… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile … Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.8 CVE-2026-23935 A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading … Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.6 CVE-2026-65349 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app m… Ipados Fix unknown Fix from $4,0002026-08-17 HIGH 8.2 CVE-2026-63409 Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP … Fix unknown Fix from $4,9002026-08-17 HIGH 8.2 CVE-2026-65832 Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-74238 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote a… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-71980 Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows… Fix unknown Fix from $4,9002026-08-17 HIGH 7.3 CVE-2026-40144 A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to versi… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.1 CVE-2026-49282 Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs d… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-17649 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-18020 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-17212 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-17226 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-o… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-16878 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-16853 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-16859 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-16861 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-55402 CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position c… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-73515 PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplyin… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.6 CVE-2026-73583 A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manage… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-17485 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. I No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-19654 A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame … No fix yet Fix from $4,9002026-08-12 MEDIUM 6.1 CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc… Enterprise Linux No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-19643 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t… Aws Software Development Kit No fix yet Fix from $4,0002026-08-12 HIGH 7.7 CVE-2026-16863 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. I after 7.6 Fix from $4,9002026-08-12 MEDIUM 6.1 CVE-2026-12232 The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id wi… No fix yet Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-18694 An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry … No fix yet Fix from $4,9002026-08-11