Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 5.3 CVE-2026-45705 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function i… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67857 open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining … Openshift Container Platform No fix yet Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-70368 A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A re… No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-69244 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C resp… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.5 CVE-2026-68742 A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining p… Openshift Container Platform No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-18583 A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.5 CVE-2026-20494 In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor h… No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-20479 In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to… No fix yet Fix from $1,9502026-08-03 HIGH 8.6 CVE-2026-10848 The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helpe… Zephyr 4.5.0+ Fix from $1,9502026-08-02 MEDIUM 5.4 CVE-2026-67306 FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_pla… No fix yet Fix from $1,6002026-08-01 HIGH 7.5 CVE-2026-67301 FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing o… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67291 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put()… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67290 FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with i… No fix yet Fix from $1,9502026-08-01 MEDIUM 5.4 CVE-2026-10773 The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faul… Zephyr 4.5.0+ Fix from $1,6002026-08-01 HIGH 8.2 CVE-2026-62959 Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-66360 The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the pro… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-66364 The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the pro… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-63550 The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-enc… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-65421 The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causi… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-66349 The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an ex… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-56758 The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling A… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past t… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-63033 A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to … No fix yet Fix from $1,6002026-07-30 MEDIUM 5.3 CVE-2026-55777 GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the pa… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.7 CVE-2026-67550 re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a… No fix yet Fix from $1,6002026-07-30 HIGH 8.1 CVE-2026-12996 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 CRITICAL 9.1 CVE-2026-13379 The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras… Openvpn 2.7.5+ Fix from $2,3002026-07-30