Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 6.5 CVE-2026-14388 Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from proces… Chrome 150.0.7871.46+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-14384 Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML… Chrome 150.0.7871.46+ Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-54908 Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic w… Patch available Fix from $1,6002026-07-01 CRITICAL 9.8 CVE-2025-15646 HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 i… Patch available Fix from $2,3002026-07-01 HIGH 7.1 CVE-2026-53346 In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a rus… Linux Kernel 6.12.94 / 6.18.36+ Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-53330 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval() [Why & H… Linux Kernel 6.18.36 / 7.0.13+ Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-44041 UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp:204, the vncWc2Mb() function… Ultravnc after 1.8.2.2 Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-54500 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uniniti… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-54592 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#each_child, when invoked recu… Mitigation only Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-56361 ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger hea… Imagemagick 6.9.13-44 / 7.1.2-19+ Fix from $1,9502026-06-30 HIGH 8.1 CVE-2026-14090 Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform … Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 MEDIUM 5.7 CVE-2026-14063 Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from pr… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-14011 Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a … Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 MEDIUM 5.3 CVE-2026-13975 Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obta… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13906 Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from proce… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.3 CVE-2026-13890 Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13873 Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from proce… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13858 Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from proce… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-13819 Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perf… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-13820 Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-9263 The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO P… Zephyr after 4.4.1 Fix from $1,9502026-06-30 HIGH 7.4 CVE-2026-10652 Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR heade… Zephyr after 4.4.1 Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-8451EPSS 16% Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured a… Netscaler Application Delivery Controller 13.1-37.272 / 13.1-63.18+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-58011 A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an in… Enterprise Linux 2.86.5+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-10817 Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is… Netscaler Application Delivery Controller 13.1-37.272 / 13.1-63.18+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-56017 JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash.… Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-43703 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8… Ipados 26.5.2+ Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-43712 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 2… Safari 26.5.2+ Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-43676 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS … Safari 26.5.2+ Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-28979 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS … Safari 26.5.2+ Fix from $1,6002026-06-29