CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
9,160 vulnerabilities with CWE-125
CVE-2026-53254
HIGH
Bluetooth: RFCOMM: validate skb length in MCC handlers
CVSS 8.1
CVE-2026-53253
HIGH
Bluetooth: bnep: reject short frames before parsing
CVSS 7.1
CVE-2026-53230
HIGH
net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVSS 8.7
CVE-2026-53224
CRITICAL
sctp: validate embedded INIT chunk and address list lengths in cookie
CVSS 9.1
CVE-2026-53179
HIGH
staging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVSS 7.1
CVE-2026-53172
HIGH
accel/ethosu: fix IFM region index out-of-bounds in command stream parser
CVSS 7.8
CVE-2026-53149
HIGH
thunderbolt: Bound root directory content to block size
CVSS 7.1
CVE-2026-53147
HIGH
thunderbolt: Validate XDomain request packet size before type cast
CVSS 8.1
CVE-2026-53138
HIGH
drm/amd/display: Bound VBIOS record-chain walk loops
CVSS 7.1
CVE-2026-13033
HIGH
Google Chrome - Out-of-bounds Read
CVSS 8.8
CVE-2026-53078
HIGH
Linux - Out-of-Bounds Access
CVSS 7.8
CVE-2026-53076
HIGH
bpf: Fix OOB in pcpu_init_value
CVSS 7.1
CVE-2026-53044
HIGH
soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables
CVSS 7.1
CVE-2026-53038
MEDIUM
ima_fs: Correctly create securityfs files for unsupported hash algos
CVSS 5.5
CVE-2026-52999
CRITICAL
netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVSS 9.1
CVE-2026-52968
HIGH
KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVSS 8.8
CVE-2026-52967
HIGH
smb/client: fix possible infinite loop and oob read in symlink_data()
CVSS 8.1
CVE-2026-52958
CRITICAL
libceph: Fix potential out-of-bounds access in osdmap_decode()
CVSS 9.1
CVE-2026-52956
HIGH
libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVSS 7.5
CVE-2026-52955
CRITICAL
libceph: Fix potential out-of-bounds access in crush_decode()
CVSS 9.8
CVE-2026-52953
HIGH
iommu/vt-d: Fix oops due to out of scope access
CVSS 7.1
CVE-2026-56370
LOW
ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact
CVSS 3.3
CVE-2026-52942
HIGH
netfilter: nf_log: validate MAC header was set before dumping it
CVSS 7.1
CVE-2026-52927
HIGH
netfilter: ebtables: fix OOB read in compat_mtw_from_user
CVSS 7.8
CVE-2026-52917
HIGH
sctp: diag: reject stale associations in dump_one path
CVSS 7.1
Details
Vulnerabilities
9,160