Total
9711 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78522 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-80079 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-80088 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2016 and 3 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-80090 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-70598 | 2026-09-08 | N/A | 3.9 LOW | ||
| Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3. | |||||
| CVE-2026-45705 | 2026-09-08 | N/A | 5.3 MEDIUM | ||
| OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1. | |||||
| CVE-2026-78503 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-78502 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-77911 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-09-08 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-72976 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-09-08 | N/A | 5.0 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-75904 | 2026-09-08 | N/A | 3.3 LOW | ||
| libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state. | |||||
| CVE-2026-78441 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-72942 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-70579 | 2026-09-08 | N/A | 7.5 HIGH | ||
| Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-69618 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69568 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69562 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-69483 | 2026-09-08 | N/A | 4.7 MEDIUM | ||
| Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69393 | 2026-09-08 | N/A | 5.7 MEDIUM | ||
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-69381 | 2026-09-08 | N/A | 4.6 MEDIUM | ||
| Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. | |||||
