CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
8,778 vulnerabilities with CWE-125
CVE-2026-43197
CRITICAL
netconsole: avoid OOB reads, msg is not nul-terminated
CVSS 9.1
CVE-2026-43190
HIGH
netfilter: xt_tcpmss: check remaining length before reading optlen
CVSS 8.2
CVE-2026-43141
HIGH
Linux - Out-of-bounds Read in NTB Switchtec MW LUT Handling
CVSS 7.1
CVE-2026-43112
HIGH
fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
CVSS 8.8
CVE-2026-43083
CRITICAL
net: ioam6: fix OOB and missing lock
CVSS 9.1
CVE-2026-30923
HIGH
libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings
CVSS 7.5
CVE-2026-43071
CRITICAL
dcache: Limit the minimal number of bucket to two
CVSS 9.1
CVE-2026-43070
HIGH
bpf: Reset register ID for BPF_END value tracking
CVSS 7.8
CVE-2026-34000
MEDIUM
X.Org X Server Xwayland - XKB Geometry Out-of-Bounds Read
CVSS 6.1
CVE-2026-6918
HIGH
Eclipse OpenJ9 0.21-0.58 - Unauthenticated Denial of Service via Crafted TCP Message
CVSS 7.5
CVE-2026-37461
HIGH
gobgp < 4.4.0 - Denial of Service via Crafted BGP UPDATE Message
CVSS 7.5
CVE-2026-34032
MEDIUM
Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVSS 5.3
CVE-2026-33857
MEDIUM
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVSS 5.3
CVE-2026-7482
CRITICAL
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
CVSS 9.1
CVE-2026-7737
MEDIUM
osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds
CVSS 5.3
CVE-2026-20447
MEDIUM
MediaTek chipset MT6768 - Privilege Escalation
CVSS 6.7
CVE-2026-7668
HIGH
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
CVSS 7.3
CVE-2026-35233
MEDIUM
Oracle Linux 8-10 - Out-of-bounds Read in ELF Parser via sh_link Field
CVSS 4.4
CVE-2026-37535
HIGH
openxc/isotp-c Out-of-bounds Read in ISO-TP Single Frame Receive Handler
CVSS 7.1
CVE-2026-42481
MEDIUM
Open CASCADE Technology V8_0_0_rc5 - Memory Corruption
CVSS 5.5
CVE-2026-42480
MEDIUM
Open CASCADE Technology V8_0_0_rc5 - DoS
CVSS 5.5
CVE-2026-43051
HIGH
HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
CVSS 8.1
CVE-2026-43048
HIGH
HID: core: Mitigate potential OOB by removing bogus memset()
CVSS 8.8
CVE-2026-43042
HIGH
mpls: add seqcount to protect the platform_label{,s} pair
CVSS 7.1
CVE-2026-43025
HIGH
netfilter: ctnetlink: ignore explicit helper on new expectations
CVSS 7.3
Details
Vulnerabilities
8,778