CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
9,159 vulnerabilities with CWE-125
CVE-2026-59145
CRITICAL
Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find
CVSS 9.1
CVE-2026-59143
MEDIUM
Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked
CVSS 6.3
CVE-2026-46600
HIGH
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVSS 7.5
CVE-2026-59142
CRITICAL
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy
CVSS 9.1
CVE-2026-59141
CRITICAL
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked
CVSS 9.1
CVE-2026-59140
CRITICAL
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths
CVSS 9.1
CVE-2026-59139
CRITICAL
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked
CVSS 9.1
CVE-2026-12548
MEDIUM
Libsoup: heap out-of-bounds read in libsoup due to integer truncation
CVSS 4.2
CVE-2026-16243
MEDIUM
Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero
CVE-2026-9499
MEDIUM
Out-of-bounds read in QTextCodec::codecForName() in Qt
CVE-2026-59842
LOW
Libssh: libssh: information disclosure via short gssapi curve25519 public key
CVSS 3.7
CVE-2026-64609
CRITICAL
Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
CVSS 9.1
CVE-2026-15903
HIGH
Google Chrome - Out-of-Bounds Access
CVSS 8.8
CVE-2026-55639
MEDIUM
xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)
CVSS 5.3
CVE-2026-55645
MEDIUM
xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)
CVSS 6.5
CVE-2026-44978
MEDIUM
xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification
CVSS 5.3
CVE-2026-35217
MEDIUM
NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds Read
CVSS 6.5
CVE-2026-26197
HIGH
Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
CVSS 7.5
CVE-2026-16254
MEDIUM
Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser
CVSS 4.3
CVE-2026-63807
HIGH
KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVSS 8.8
CVE-2026-63799
HIGH
sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
CVSS 7.8
CVE-2026-63796
HIGH
ocfs2: reject oversized group bitmap descriptors
CVSS 8.8
CVE-2026-53402
HIGH
fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVSS 7.1
CVE-2026-53390
HIGH
ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVSS 8.1
CVE-2026-16013
MEDIUM
liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
CVSS 5.3
Details
Vulnerabilities
9,159