Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.1 CVE-2026-40026 The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts le… The Sleuth Kit 4.14.0+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-28386 Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of u… OpenSSL 3.6.2+ Fix from $1,9502026-04-07 HIGH 7.8 CVE-2026-32863 There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerabil… Labview after 2022 Fix from $1,9502026-04-07 HIGH 7.8 CVE-2026-32864 There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may resul… Labview after 2022 Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-5735 Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that wi… Firefox 149.0.2+ Fix from $2,3002026-04-07 MEDIUM 6.1 CVE-2026-35444 SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF… Sdl Image 2026-04-02+ Fix from $1,6002026-04-06 HIGH 7.5 CVE-2026-35203 ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload base… Zlmediakit 2026-03-29+ Fix from $1,9502026-04-06 MEDIUM 5.9 CVE-2026-35201 Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes a… Rdiscount 2.2.7.4+ Fix from $1,6002026-04-06 HIGH 7.1 CVE-2026-35170 openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader()… Openfpgaloader after 1.1.1 Fix from $1,9502026-04-06 HIGH 7.1 CVE-2026-35176 openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection(… Openfpgaloader after 1.1.1 Fix from $1,9502026-04-06 HIGH 7.8 CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From… Openexr 3.2.7 / 3.3.9+ Fix from $1,9502026-04-06 HIGH 7.1 CVE-2026-5673 A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically i… Enterprise Linux No fix yet Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-31405 In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-06 MEDIUM 5.3 CVE-2026-34776 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and… Electron 38.8.6 / 39.8.1+ Fix from $1,6002026-04-04 HIGH 7.5 CVE-2026-34824 Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resourc… Mesop 1.2.5+ Fix from $1,9502026-04-03 HIGH 8.1 CVE-2026-31393 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_in… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-03 HIGH 7.1 CVE-2026-31395 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT… Linux Kernel 6.18.20 / 6.19.10+ Fix from $1,9502026-04-03 CRITICAL 9.1 CVE-2026-23455 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ9… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-03 HIGH 8.2 CVE-2026-23456 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-28815 A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing … Swift Crypto 4.3.1+ Fix from $1,9502026-04-03 MEDIUM 6.3 CVE-2025-43210 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequ… Ipados 2.6 / 11.6+ Fix from $1,6002026-04-02 HIGH 8.2 CVE-2026-34608 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() func… Nanomq 0.24.10+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-35038 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerabi… Signal K Server 2.24.0+ Fix from $1,6002026-04-02 HIGH 7.5 CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers t… Mbed Tls 3.6.6+ Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-5342 A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw… Libraw 0.22.1+ Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-5315 A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the … Stb Truetype.h after 1.26 Fix from $1,9502026-04-02 MEDIUM 5.5 CVE-2026-32927 V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead… V Sft after 6.2.10.0 Fix from $1,6002026-04-01 MEDIUM 5.5 CVE-2026-32929 V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information di… V Sft after 6.2.10.0 Fix from $1,6002026-04-01 HIGH 8.8 CVE-2026-5314 A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component… Stb Truetype.h after 1.26 Fix from $1,9502026-04-01 MEDIUM 5.5 CVE-2026-32926 V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to info… V Sft after 6.2.10.0 Fix from $1,6002026-04-01