Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,311 CVEs tagged with CWE-125694 Critical, 3,868 High, 4,235 Medium, 511 Low, 3 Unrated.

CVE-2026-63799

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path In mm_cid_fixup_cpus_to_tasks(), when r…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-63796

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors ocfs2_validate_gd_parent() only bounds bg_bits against the p…

CVSS 8.8 · High
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort

CVE-2026-53402

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() When fbcon_do_set_font() fails (e.g.,…

CVSS 7.1 · High
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort

CVE-2026-53390

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl()…

CVSS 8.1 · High
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2026-16013

Published Jul 17, 2026

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-44452

Published Jul 16, 2026

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-57077

Published Jul 16, 2026

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference t…

CVSS 7.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57075

Published Jul 16, 2026

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes the…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-60073

Published Jul 16, 2026

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of k…

CVSS 5.2 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-57896

Published Jul 16, 2026

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could lead to…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-60140

Published Jul 16, 2026

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can lead to ex…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-57074

Published Jul 16, 2026

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or elem…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-57073

Published Jul 16, 2026

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or ele…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2026-47729

Published Jul 16, 2026

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulner…

CVSS 6.5 · Medium
evidence mentions
13
Buzz score
46.4
Vendor/product tagsBeta · best-effort

CVE-2026-45612

Published Jul 16, 2026

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-38754

Published Jul 15, 2026

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-62353

Published Jul 15, 2026

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backs…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62351

Published Jul 15, 2026

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contL…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10673

Published Jul 15, 2026

The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (OA) SPI mode by copying device…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-61862

Published Jul 15, 2026

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not prin…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-15030

Published Jul 15, 2026

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the int…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47979

Published Jul 14, 2026

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensi…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15714

Published Jul 14, 2026

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-m…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-15720

Published Jul 14, 2026

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Showing 251-275 of 9,311 CVEsPage 11 of 373