Total
9711 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69376 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69369 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69353 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69344 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-85455 | 2026-09-08 | N/A | 8.2 HIGH | ||
| MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication. | |||||
| CVE-2026-85444 | 2026-09-08 | N/A | 7.5 HIGH | ||
| MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory. | |||||
| CVE-2026-66349 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition. | |||||
| CVE-2026-63033 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. | |||||
| CVE-2026-61893 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. | |||||
| CVE-2026-66360 | 2026-09-08 | N/A | 7.5 HIGH | ||
| The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition. | |||||
| CVE-2026-56758 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer. | |||||
| CVE-2026-69303 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-31912 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures. | |||||
| CVE-2026-0799 | 2026-09-08 | N/A | 8.7 HIGH | ||
| In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures. | |||||
| CVE-2026-77492 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-72937 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-67624 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-64200 | 2026-09-08 | N/A | 7.8 HIGH | ||
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | |||||
| CVE-2026-64198 | 2026-09-08 | N/A | 7.8 HIGH | ||
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | |||||
| CVE-2026-64199 | 2026-09-08 | N/A | 7.8 HIGH | ||
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | |||||
