Vulnerabilities (CVE)

Filtered by CWE-125
Total 9711 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69609 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69572 2026-09-08 N/A 5.7 MEDIUM
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.
CVE-2026-69443 2026-09-08 N/A 7.5 HIGH
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
CVE-2026-69428 2026-09-08 N/A 7.5 HIGH
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
CVE-2026-69390 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69372 2026-09-08 N/A 5.7 MEDIUM
Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.
CVE-2026-69367 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-69345 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-69329 2026-09-08 N/A 7.5 HIGH
Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
CVE-2026-69318 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.
CVE-2026-69317 2026-09-08 N/A 5.7 MEDIUM
Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
CVE-2026-69308 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-68898 2026-09-08 N/A 6.5 MEDIUM
Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.
CVE-2026-68891 2026-09-08 N/A 4.7 MEDIUM
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-68887 2026-09-08 N/A 7.5 HIGH
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
CVE-2026-68881 2026-09-08 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-68874 2026-09-08 N/A 5.7 MEDIUM
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.
CVE-2026-67630 2026-09-08 N/A 6.5 MEDIUM
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67629 2026-09-08 N/A 6.5 MEDIUM
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-55777 2026-09-08 N/A N/A
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11.