Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.1 CVE-2026-44064 An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or c… Mitigation only Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-44066 Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to ob… Mitigation only Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-9121 Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 148.0.7778.178+ Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-9122 Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from … Chrome 148.0.7778.179+ Fix from $1,6002026-05-20 HIGH 7.5 CVE-2026-5946 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 MEDIUM 5.3 CVE-2026-32792 NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnsc… Unbound 1.25.1+ Fix from $1,6002026-05-20 CRITICAL 9.8 CVE-2026-24213 NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit… Triton Inference Server 26.03+ Fix from $2,3002026-05-20 HIGH 8.1 CVE-2026-43618 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked … Rsync after 3.4.2 Fix from $1,9502026-05-20 MEDIUM 5.5 CVE-2026-43620 Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rs… Rsync after 3.4.2 Fix from $1,6002026-05-20 HIGH 7.1 CVE-2026-32882 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in… Mitigation only Fix from $1,9502026-05-19 CRITICAL 9.8 CVE-2026-33642 Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds… Kitty 0.47.0+ Fix from $2,3002026-05-19 MEDIUM 6.5 CVE-2026-32738 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chun… Libheif 1.22.0+ Fix from $1,6002026-05-19 MEDIUM 6.2 CVE-2026-38719 OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFor… Mitigation only Fix from $1,6002026-05-18 CRITICAL 9.1 CVE-2026-8686 Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a c… Coremqtt Mitigation only Fix from $2,3002026-05-15 MEDIUM 5.8 CVE-2025-29937 An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location po… Mitigation only Fix from $1,6002026-05-15 MEDIUM 6.9 CVE-2025-48520 An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.3 CVE-2026-8543 Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 MEDIUM 5.3 CVE-2026-8546 Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer proc… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 MEDIUM 5.3 CVE-2026-8535 Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 MEDIUM 5.3 CVE-2026-8541 Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potent… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 HIGH 8.8 CVE-2026-43909 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a… Openimageio 3.0.18.0 / 3.1.13.0+ Fix from $1,9502026-05-14 MEDIUM 5.5 CVE-2026-43996 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a… Openimageio 3.0.18.0 / 3.1.13.0+ Fix from $1,6002026-05-14 HIGH 7.8 CVE-2025-65087 An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that… Argon after 12.6.1204.216 Fix from $1,9502026-05-12 HIGH 7.8 CVE-2025-65088 An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that… Argon after 12.6.1204.216 Fix from $1,9502026-05-12 HIGH 7.1 CVE-2026-42446 NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image … Nanazip 6.0.1698.0+ Fix from $1,9502026-05-12 MEDIUM 6.2 CVE-2026-40380 Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,6002026-05-12 HIGH 7.8 CVE-2026-40360 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20128+ Fix from $1,9502026-05-12 MEDIUM 5.4 CVE-2026-35423 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-35419 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.8390 / 10.0.26100.32772+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-34663 Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. … Illustrator 29.8.7 / 30.4+ Fix from $1,6002026-05-12