Total
334 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-50485 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-21 | N/A | 4.5 MEDIUM |
| Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | |||||
| CVE-2026-57968 | 1 Microsoft | 1 Windows Subsystem For Linux | 2026-07-20 | N/A | 7.8 HIGH |
| Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50341 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-20 | N/A | 5.5 MEDIUM |
| Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |||||
| CVE-2024-30069 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2026-07-20 | N/A | 4.7 MEDIUM |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | |||||
| CVE-2026-47088 | 2026-07-17 | N/A | 3.1 LOW | ||
| An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user. | |||||
| CVE-2026-59840 | 1 Fortinet | 2 Fortios, Fortiproxy | 2026-07-16 | N/A | 4.3 MEDIUM |
| A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here> | |||||
| CVE-2025-43892 | 1 Fortinet | 2 Fortios, Fortiproxy | 2026-07-16 | N/A | 4.3 MEDIUM |
| A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. | |||||
| CVE-2026-55036 | 1 Microsoft | 7 365 Apps, Excel, Microsoft 365 and 4 more | 2026-07-16 | N/A | 7.8 HIGH |
| Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-62353 | 2026-07-15 | N/A | 5.4 MEDIUM | ||
| TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14. | |||||
| CVE-2026-49854 | 2026-07-15 | N/A | 5.3 MEDIUM | ||
| Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. | |||||
| CVE-2026-41898 | 1 Rust-openssl Project | 1 Rust-openssl | 2026-07-15 | N/A | 5.3 MEDIUM |
| rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78. | |||||
| CVE-2026-4371 | 1 Mozilla | 1 Thunderbird | 2026-07-15 | N/A | 7.4 HIGH |
| A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. | |||||
| CVE-2026-28364 | 1 Ocaml | 1 Ocaml | 2026-07-15 | N/A | 7.9 HIGH |
| In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. | |||||
| CVE-2026-6238 | 1 Gnu | 1 Glibc | 2026-07-14 | N/A | 6.5 MEDIUM |
| The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions. | |||||
| CVE-2026-50813 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path | |||||
| CVE-2026-21379 | 1 Qualcomm | 94 Aqt1000, Aqt1000 Firmware, Cologne and 91 more | 2026-07-07 | N/A | 7.8 HIGH |
| Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | |||||
| CVE-2025-60729 | 1 Perfree | 1 Perfreeblog | 2026-07-05 | N/A | 5.3 MEDIUM |
| PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | |||||
| CVE-2026-58013 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-07-02 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. | |||||
| CVE-2026-58012 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-07-02 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary. | |||||
| CVE-2026-58010 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-07-02 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary. | |||||
