Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,206 CVEs tagged with CWE-125693 Critical, 3,826 High, 4,172 Medium, 510 Low, 5 Unrated.

CVE-2026-54058

Published Jul 14, 2026

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled heade…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-50300

Published Jul 14, 2026

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49794

Published Jul 14, 2026

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVSS 4.6 · Medium
evidence mentions
5
Buzz score
32.4

CVE-2026-60082

Published Jul 14, 2026

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the interna…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
34.4

CVE-2026-59198

Published Jul 14, 2026

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowin…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-53379

Published Jul 14, 2026

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10672

Published Jul 14, 2026

subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) wi…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-53566

Published Jul 14, 2026

Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12478

Published Jul 14, 2026

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A m…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
24.1

CVE-2026-58102

Published Jul 13, 2026

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensi…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-51541

Published Jul 13, 2026

OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a val…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-51537

Published Jul 13, 2026

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An atta…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-60103

Published Jul 13, 2026

Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file w…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-57432

Published Jul 13, 2026

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times…

CVSS 8.4 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-57158

Published Jul 10, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-57157

Published Jul 10, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-14461

Published Jul 10, 2026

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by return…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-40454

Published Jul 10, 2026

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malfor…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-11404

Published Jul 9, 2026

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte f…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15185

Published Jul 9, 2026

A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-58307

Published Jul 9, 2026

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-58304

Published Jul 9, 2026

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15114

Published Jul 8, 2026

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromiu…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-29007

Published Jul 8, 2026

U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read be…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort
Showing 226-250 of 9,206 CVEsPage 10 of 369