Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.5 CVE-2026-66729 facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attacke… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-66731 facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated … No fix yet Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-17572 Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of s… Hdf5 No fix yet Fix from $1,6002026-07-27 MEDIUM 5.6 CVE-2026-15003 A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker pro… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.1 CVE-2026-58023 Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrad… Thrift 0.24.0+ Fix from $2,3002026-07-27 CRITICAL 9.1 CVE-2026-58662 Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift… Thrift 0.24.0+ Fix from $2,3002026-07-27 HIGH 7.8 CVE-2026-64277 In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initiali… Linux Kernel 5.10.261 / 5.15.212+ Fix from $1,9502026-07-25 MEDIUM 6.5 CVE-2026-66337 A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when … No fix yet Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-66033 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in… Libssh2 after 1.11.1 Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-66034 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit… Libssh2 after 1.11.1 Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-64255 In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three… Linux Kernel 6.18.38 / 7.1.3+ Fix from $1,9502026-07-24 HIGH 8.4 CVE-2026-64247 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checkin… Linux Kernel 6.6.144 / 6.12.95+ Fix from $1,9502026-07-24 HIGH 7.1 CVE-2026-64237 In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use Ensure that the firmware fi… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-64223 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTLM maps ieee80211_tid_to_link… Linux Kernel 6.12.92 / 6.18.34+ Fix from $1,9502026-07-24 HIGH 7.1 CVE-2026-64209 In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tb… Linux Kernel 7.0.11+ Fix from $1,9502026-07-24 HIGH 8.7 CVE-2026-55732 Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and … No fix yet Fix from $1,9502026-07-24 HIGH 8.2 CVE-2026-16002 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-65918 PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor … No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-16768 A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds r… No fix yet Fix from $1,6002026-07-23 HIGH 7.7 CVE-2026-43820 NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backe… No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-13077 A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi… MongoDB No fix yet Fix from $1,9502026-07-22 HIGH 7.1 CVE-2026-64833 FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buf… Ffmpeg after 8.1.2 Fix from $1,9502026-07-22 HIGH 7.1 CVE-2026-48029 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile v… Libheif 1.22.0+ Fix from $1,9502026-07-22 CRITICAL 9.6 CVE-2026-16419 Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox … Chrome 150.0.7871.182+ Fix from $2,3002026-07-21 MEDIUM 6.1 CVE-2026-47251 libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in … Libheif 1.22.0+ Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-47254 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.… Libheif 1.22.0+ Fix from $1,6002026-07-21 HIGH 7.6 CVE-2026-10680 The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2cap_br.c validated the m… Zephyr 4.3.1+ Fix from $1,9502026-07-21 MEDIUM 6.9 CVE-2026-45383 libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists … No fix yet Fix from $1,6002026-07-21 MEDIUM 6.9 CVE-2026-45382 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/dec… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.3 CVE-2026-59143 Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_conta… No fix yet Fix from $1,6002026-07-21