Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Fory CRITICAL 9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Traffic Server MEDIUM 6.5
CVE-2026-58160

Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 …

Fix: 9.2.15 / 10.1.4+
Fix from $1,600 2026-07-29
Thrift CRITICAL 9.1
CVE-2026-58023

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrad…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-58662

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Fory CRITICAL 9.1
CVE-2026-64609

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the b…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
HTTP Server HIGH 7.3
CVE-2026-44185

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server MEDIUM 6.5
CVE-2026-43951

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP…

Fix: after 2.4.67
Fix from $1,600 2026-06-08
HTTP Server MEDIUM 5.3
CVE-2026-33857

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recomme…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server MEDIUM 5.3
CVE-2026-34032

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
Thrift HIGH 8.2
CVE-2026-41604

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift MEDIUM 6.5
CVE-2026-41607

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,600 2026-04-28
Nimble HIGH 7.5
CVE-2024-51569

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access wh…

Fix: 1.8.0+
Fix from $1,950 2024-11-26
Nimble MEDIUM 5.0
CVE-2024-47250

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsin…

Fix: 1.8.0+
Fix from $1,600 2024-11-26
Traffic Server MEDIUM 6.5
CVE-2018-9481

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d…

Fix: 7.1.10 / 8.0.7+
Fix from $1,600 2024-11-20
Inlong HIGH 7.5
CVE-2023-24977

Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are ad…

Fix: after 1.5.0
Fix from $1,950 2023-02-01
HTTP Server MEDIUM 5.3
CVE-2022-28330

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

Fix: after 2.4.53
Fix from $1,600 2022-06-09
HTTP Server HIGH 7.5
CVE-2021-36160EPSS 63%

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Ser…

Fix: 2.4.49+
Fix from $1,950 2021-09-16
Portable Runtime HIGH 7.1
CVE-2021-35940

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for thi…

Patch available
Fix from $1,950 2021-08-23
Bookkeeper HIGH 7.1
CVE-2020-23922

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

Fix: after 5.1.4
Fix from $1,950 2021-04-21
Thrift HIGH 7.5
CVE-2019-0210EPSS 7%

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Fix: after 0.12.0
Fix from $1,950 2019-10-29
HTTP Server HIGH 7.5
CVE-2018-1303EPSS 70%

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing…

Fix: after 2.4.29
Fix from $1,950 2018-03-26
Portable Runtime HIGH 7.1
CVE-2017-12613

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…

Fix: 1.7.0+
Fix from $1,950 2017-10-24
HTTP Server HIGH 7.5
CVE-2017-7668EPSS 57%

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to searc…

Patch available
Fix from $1,950 2017-06-20
Openoffice HIGH 7.8
CVE-2016-1513

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute…

Fix: after 4.1.2
Fix from $1,950 2016-08-05
HTTP Server MEDIUM 5.0
CVE-2007-3847EPSS 13%

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a …

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-08-23