Vulnerabilities (CVE)

Filtered by CWE-126
Total 521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-83951 1 Microsoft 5 365 Apps, Office 2019, Office 2021 and 2 more 2026-09-08 N/A 5.5 MEDIUM
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-69719 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-09-08 N/A 6.5 MEDIUM
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-72932 2026-09-08 N/A 7.5 HIGH
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
CVE-2026-69794 2026-09-08 N/A 5.5 MEDIUM
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CVE-2026-69474 2026-09-08 N/A 4.8 MEDIUM
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
CVE-2026-69316 2026-09-08 N/A 4.7 MEDIUM
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
CVE-2026-18238 2026-09-08 N/A 5.0 MEDIUM
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
CVE-2026-65933 2026-09-08 N/A N/A
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
CVE-2026-65936 2026-09-08 N/A N/A
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.
CVE-2026-84640 1 Mozilla 1 Thunderbird 2026-09-03 N/A 7.5 HIGH
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-5260 2026-09-03 N/A 8.2 HIGH
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
CVE-2026-76885 1 Wireshark 1 Wireshark 2026-08-31 N/A 3.1 LOW
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76884 1 Wireshark 1 Wireshark 2026-08-31 N/A 3.1 LOW
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-18024 1 Postgresql 1 Postgresql 2026-08-29 N/A 4.3 MEDIUM
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14678 1 Postgresql 1 Postgresql 2026-08-29 N/A 4.3 MEDIUM
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-53414 2026-08-28 N/A 6.5 MEDIUM
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
CVE-2026-69550 1 Microsoft 1 Windows App 2026-08-27 N/A 6.5 MEDIUM
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-41992 1 Gnu 1 Gzip 2026-08-27 N/A 7.5 HIGH
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.
CVE-2026-70652 2026-08-21 N/A N/A
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.
CVE-2026-20846 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-19 N/A 7.5 HIGH
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.