Total
9704 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68784 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68781 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68780 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68779 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68778 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68777 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-86137 | 1 Xmlsoft | 1 Libxml2 | 2026-09-15 | N/A | 2.9 LOW |
| In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | |||||
| CVE-2026-67645 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-64736 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-09-15 | N/A | 7.1 HIGH |
| An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory. | |||||
| CVE-2026-84543 | 2026-09-15 | N/A | 7.5 HIGH | ||
| An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory. | |||||
| CVE-2026-84516 | 2026-09-15 | N/A | 8.1 HIGH | ||
| An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory. | |||||
| CVE-2026-19654 | 2 Redhat, Rsyslog | 2 Enterprise Linux, Rsyslog | 2026-09-15 | N/A | 7.5 HIGH |
| A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. | |||||
| CVE-2026-67636 | 1 Microsoft | 3 Sql Server 2019, Sql Server 2022, Sql Server 2025 | 2026-09-15 | N/A | 8.5 HIGH |
| Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-67389 | 1 Microsoft | 2 Sql Server 2022, Sql Server 2025 | 2026-09-15 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-90557 | 2026-09-15 | N/A | 6.1 MEDIUM | ||
| Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded. | |||||
| CVE-2026-52296 | 2026-09-15 | N/A | 2.9 LOW | ||
| FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c. | |||||
| CVE-2026-19086 | 2026-09-15 | N/A | 3.3 LOW | ||
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. | |||||
| CVE-2026-91958 | 2026-09-15 | N/A | 6.6 MEDIUM | ||
| FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp. | |||||
| CVE-2026-79514 | 1 Gpac | 1 Gpac | 2026-09-15 | N/A | 6.5 MEDIUM |
| An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | |||||
| CVE-2026-79522 | 1 Gpac | 1 Gpac | 2026-09-15 | N/A | 6.5 MEDIUM |
| An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | |||||
