Vulnerabilities (CVE)

Filtered by CWE-125
Total 9133 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48188 1 Gnu 1 Pspp 2026-06-17 N/A 2.9 LOW
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
CVE-2025-48072 1 Openexr 1 Openexr 2026-06-17 N/A 9.1 CRITICAL
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a heap-based buffer overflow during a read operation due to bad pointer math when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. This is fixed in version 3.3.3.
CVE-2025-48002 1 Microsoft 2 Windows 11 24h2, Windows Server 2025 2026-06-17 N/A 5.7 MEDIUM
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.
CVE-2025-47996 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-06-17 N/A 7.8 HIGH
Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
CVE-2025-47978 1 Microsoft 3 Windows Server 2022, Windows Server 2022 23h2, Windows Server 2025 2026-06-17 N/A 6.5 MEDIUM
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
CVE-2025-47914 1 Golang 1 Crypto 2026-06-17 N/A 5.3 MEDIUM
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-47873 1 Canva 1 Affinity 2026-06-17 N/A 6.1 MEDIUM
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
CVE-2025-47816 1 Gnu 1 Pspp 2026-06-17 N/A 2.9 LOW
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.
CVE-2025-47757 1 Fujielectric 1 Monitouch V-sft 2026-06-17 N/A 7.8 HIGH
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
CVE-2025-47756 1 Fujielectric 1 Monitouch V-sft 2026-06-17 N/A 7.8 HIGH
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
CVE-2025-47755 1 Fujielectric 1 Monitouch V-sft 2026-06-17 N/A 7.8 HIGH
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!VS4_SaveEnvFile function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
CVE-2025-47754 1 Fujielectric 1 Monitouch V-sft 2026-06-17 N/A 7.8 HIGH
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!Conv_Macro_Data function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
CVE-2025-47753 1 Fujielectric 1 Monitouch V-sft 2026-06-17 N/A 7.8 HIGH
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
CVE-2025-47406 1 Qualcomm 62 Cologne, Cologne Firmware, Fastconnect 6700 and 59 more 2026-06-17 N/A 6.1 MEDIUM
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47403 1 Qualcomm 514 Ar8035, Ar8035 Firmware, Cologne and 511 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47402 1 Qualcomm 188 Ar8035, Ar8035 Firmware, Cologne and 185 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing a received frame with an excessively large authentication information element.
CVE-2025-47401 1 Qualcomm 490 Ar8035, Ar8035 Firmware, Cologne and 487 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-47295 1 Fortinet 1 Fortios 2026-06-17 N/A 3.7 LOW
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
CVE-2025-47219 1 Gstreamer 1 Gstreamer 2026-06-17 N/A 8.1 HIGH
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.
CVE-2025-47183 1 Gstreamer 1 Gstreamer 2026-06-17 N/A 6.6 MEDIUM
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.