Total
334 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-63091 | 1 Proftpd | 1 Proftpd | 2026-07-30 | N/A | 6.5 MEDIUM |
| ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process memory into the uploaded file. In tested configurations, the disclosed data contains libc, libcrypto, and PIE pointers sufficient to derive their randomized base addresses, thereby bypassing ASLR and enabling reliable exploitation of memory corruption vulnerabilities in the same process. | |||||
| CVE-2026-44185 | 1 Apache | 1 Http Server | 2026-07-28 | N/A | 7.3 HIGH |
| Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |||||
| CVE-2026-55970 | 1 Apache | 1 Thrift | 2026-07-27 | N/A | 6.5 MEDIUM |
| Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | |||||
| CVE-2026-24028 | 1 Powerdns | 1 Dnsdist | 2026-07-25 | N/A | 5.3 MEDIUM |
| An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure. | |||||
| CVE-2026-5260 | 2026-07-24 | N/A | 8.2 HIGH | ||
| A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure. | |||||
| CVE-2026-25646 | 1 Libpng | 1 Libpng | 2026-07-23 | N/A | 8.1 HIGH |
| LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55. | |||||
| CVE-2026-45460 | 1 Microsoft | 6 365 Apps, 365 Copilot, Microsoft 365 and 3 more | 2026-07-23 | N/A | 4.7 MEDIUM |
| Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-42828 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-07-23 | N/A | 7.8 HIGH |
| Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-11787 | 1 Redhat | 3 389 Directory Server, Directory Server, Enterprise Linux | 2026-07-23 | N/A | 5.0 MEDIUM |
| A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | |||||
| CVE-2026-50435 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-23 | N/A | 7.8 HIGH |
| Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-55238 | 1 Neutrinolabs | 1 Xrdp | 2026-07-22 | N/A | 5.3 MEDIUM |
| xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service. This issue has been fixed in version 0.10.6.1. | |||||
| CVE-2026-45684 | 1 Opentelemetry | 1 Ebpf Instrumentation | 2026-07-22 | N/A | 4.9 MEDIUM |
| OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy length. When log injection is enabled, a crafted multi-segment writev call can make OBI read and overwrite memory beyond the first segment. This issue has been patched in version 0.9.0. | |||||
| CVE-2025-59609 | 1 Qualcomm | 374 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Ar8035 and 371 more | 2026-07-22 | N/A | 5.5 MEDIUM |
| Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | |||||
| CVE-2026-50468 | 1 Microsoft | 1 Sql Server 2025 | 2026-07-22 | N/A | 6.5 MEDIUM |
| Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-50504 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 6.5 MEDIUM |
| Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-50475 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 5.5 MEDIUM |
| Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-50445 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 6.5 MEDIUM |
| Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-50402 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.8 HIGH |
| Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50383 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-22 | N/A | 6.1 MEDIUM |
| Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-50372 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.0 HIGH |
| Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | |||||
