Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,105 CVEs tagged with CWE-125672 Critical, 3,779 High, 4,147 Medium, 504 Low, 3 Unrated.

CVE-2026-66759

Published Jul 27, 2026

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if t…

CVSS 7.1 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-66731

Published Jul 27, 2026

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-66729

Published Jul 27, 2026

facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17572

Published Jul 27, 2026

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted H…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15003

Published Jul 27, 2026

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-…

CVSS 5.6 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-17512

Published Jul 27, 2026

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-58662

Published Jul 27, 2026

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are re…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-58023

Published Jul 27, 2026

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fix…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-66337

Published Jul 24, 2026

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP respons…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-66034

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-66033

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a m…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-55732

Published Jul 24, 2026

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56391

Published Jul 24, 2026

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscal…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-16002

Published Jul 23, 2026

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65918

Published Jul 23, 2026

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped…

CVSS 7.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-16768

Published Jul 23, 2026

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-43820

Published Jul 23, 2026

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not a…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13077

Published Jul 22, 2026

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64833

Published Jul 22, 2026

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-48029

Published Jul 22, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinat…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-16473

Published Jul 22, 2026

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. T…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-16419

Published Jul 21, 2026

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47254

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds ch…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47251

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it add…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-10680

Published Jul 21, 2026

The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2cap_br.c validated the minimum command size against bu…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0
Showing 1-25 of 9,105 CVEsPage 1 of 365