Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,311 CVEs tagged with CWE-125694 Critical, 3,868 High, 4,235 Medium, 511 Low, 3 Unrated.

CVE-2026-65832

Published Aug 17, 2026

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy:…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-63409

Published Aug 17, 2026

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOpti…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-74238

Published Aug 17, 2026

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-71980

Published Aug 17, 2026

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjac…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-12630

Published Aug 17, 2026

Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is lo…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-40144

Published Aug 17, 2026

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient valida…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-19955

Published Aug 16, 2026

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds re…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-49282

Published Aug 14, 2026

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected archit…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-18020

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17649

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17226

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17212

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16878

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16861

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16859

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16853

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55402

Published Aug 13, 2026

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73515

Published Aug 13, 2026

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffe…

CVSS 7.2 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-14256

Published Aug 13, 2026

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a syst…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-73583

Published Aug 13, 2026

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communicatio…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-17485

Published Aug 12, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-19654

Published Aug 12, 2026

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2026-73434

Published Aug 12, 2026

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by divi…

CVSS 6.1 · Medium
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-19643

Published Aug 12, 2026

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that pr…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-16863

Published Aug 12, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 9,311 CVEsPage 1 of 373