CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
8,471 vulnerabilities with CWE-125
CVE-2026-28528
MEDIUM
BlueKitchen BTstack < 1.8.1 AVRCP Browsing Target GET_FOLDER_ITEMS Handler OOB Read / Undefined Behavior
CVSS 4.6
CVE-2026-28527
LOW
BlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB Read
CVSS 3.5
CVE-2026-28526
LOW
BlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB Read
CVSS 3.5
CVE-2026-32984
LOW
Heap buffer overflow in wazuh-authd
CVSS 3.5
CVE-2026-33669
CRITICAL
SiYuan has Arbitrary Document Reading within the Publishing Service
CVSS 9.8
CVE-2026-3622
HIGH
Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N
CVSS 7.5
CVE-2026-33636
HIGH
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
CVSS 7.6
CVE-2026-26008
HIGH
EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes
CVSS 7.5
CVE-2026-33515
MEDIUM
Squid has issues in ICP message handling
CVSS 6.5
CVE-2026-23388
HIGH
Squashfs: check metadata block offset is within range
CVSS 7.1
CVE-2026-23363
HIGH
wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23327
HIGH
cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
CVSS 7.1
CVE-2026-23325
HIGH
wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-23318
HIGH
ALSA: usb-audio: Use correct version for UAC3 header validation
CVSS 7.1
CVE-2026-23315
HIGH
wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()
CVSS 7.1
CVE-2026-28890
MEDIUM
Apple Xcode < 26.4 - Out-of-Bounds Access
CVSS 5.5
CVE-2026-28859
MEDIUM
Apple Safari < 26.4 - Denial of Service
CVSS 4.3
CVE-2026-28857
MEDIUM
Apple Safari < 26.4 - Denial of Service
CVSS 6.5
CVE-2026-28832
HIGH
Apple Macos < 14.8.5 - Out-of-Bounds Access
CVSS 8.4
CVE-2026-20690
MEDIUM
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 6.5
CVE-2026-20657
MEDIUM
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 6.5
CVE-2026-32853
HIGH
LibVNCServer UltraZip Encoding Heap Out-of-bounds Read
CVSS 8.1
CVE-2026-32647
HIGH
NGINX ngx_http_mp4_module vulnerability
CVSS 7.8
CVE-2026-4753
CRITICAL
Out-of-bounds Read in slajerek RetroDebugger
CVSS 9.1
CVE-2026-4750
CRITICAL
Out-of-bounds Read in fabiangreffrath woof
CVSS 9.1
Details
Vulnerabilities
8,471