By weakness (CWE)

CWE-125: related vulnerabilities

CVEs classified under CWE-125. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

286 published vulnerabilities · page 1 of 3

  • CVE-2026-10941HIGH 8.8

    A memory access vulnerability in the Skia graphics engine used by Google Chrome allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The attack requires user interaction (clicking a link or visiting a site) but needs no special privileges. While the code runs in a sandbox environment, successful exploitation could compromise data confidentiality, integrity, and availability within that isolated context.

  • CVE-2026-11077HIGH 8.8

    A flaw in the Dawn graphics component of Google Chrome allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability requires user interaction (clicking a link or visiting a page) but doesn't require any special privileges. Once exploited, an attacker gains the same permissions as the Chrome process, potentially allowing them to steal data or compromise the system.

  • CVE-2026-11091HIGH 8.8

    A flaw in Google Chrome's graphics rendering engine (Dawn) allows attackers to trick users into visiting malicious web pages that can read sensitive data, modify files, or crash the browser. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted website—but once triggered, it bypasses Chrome's memory protections. This affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-11191HIGH 8.8

    A memory safety flaw in Chrome's ANGLE graphics library allows attackers to access memory beyond intended boundaries when a user visits a malicious webpage. An attacker can craft HTML that exploits this out-of-bounds read or write to leak sensitive data, crash the browser, or execute code with the privileges of the Chrome process. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-11279HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain an out-of-bounds read vulnerability in the DevTools component that allows an attacker to execute arbitrary code within the Chrome sandbox. An attacker would need to trick a user into visiting a crafted HTML page, but would not need any special privileges or system access. While Chromium's internal severity assessment is Low, the CVSS 3.1 score of 8.8 reflects the high severity due to the potential for code execution within a restricted sandbox environment.

  • CVE-2026-11301HIGH 8.8

    A vulnerability in Google Chrome's LiveCaption feature allows attackers to access memory outside safe boundaries by sending specially crafted network traffic. While Chrome assigned this a low severity rating internally, the vulnerability can lead to information disclosure, data corruption, or system crashes depending on what memory region is accessed. The attack requires user interaction—the user must be running a vulnerable Chrome version and receive the malicious traffic—but no special privileges are needed from the attacker's perspective.

  • CVE-2026-13033HIGH 8.8

    A memory safety vulnerability in Google Chrome's interest groups feature allows attackers to read and write data outside intended memory boundaries. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to execute arbitrary code on the victim's machine. The vulnerability affects Chrome versions before 149.0.7827.197 and is classified as critical by Chrome's security team.

  • CVE-2026-14422HIGH 8.8

    A memory safety vulnerability exists in Chrome's Tint rendering component that allows attackers to read and write beyond allocated memory boundaries. When a user visits a malicious website, the attacker can craft HTML that triggers out-of-bounds memory access, potentially compromising confidentiality, integrity, and availability. The vulnerability requires user interaction (visiting a malicious page) but no special privileges, making it a significant risk for typical browsing scenarios.

  • CVE-2026-15114HIGH 8.8

    A memory safety vulnerability in Google Chrome's video codec processing allows attackers to corrupt heap memory by tricking users into opening a specially crafted video file. The flaw combines an out-of-bounds read with an out-of-bounds write, potentially enabling arbitrary code execution on affected systems. Users must update to Chrome 150.0.7871.115 or later to patch the issue.

  • CVE-2026-52968HIGH 8.8

    A memory access error in the Linux kernel's KVM hypervisor implementation for IBM System z (s390) PCI device handling allows a local privileged user to read or modify kernel memory outside intended boundaries. The bug stems from incorrect pointer arithmetic that scales offsets twice when accessing internal device management tables, causing the kernel to read from or write to the wrong memory location when handling PCI device interrupts. This can crash the system or potentially allow privilege escalation on affected virtualization hosts.

  • CVE-2026-53360HIGH 8.8

    This Linux kernel vulnerability affects AMD SEV-SNP (Secure Encrypted Virtualization with Secure Nested Paging) virtual machines. A malicious guest operating system can exploit improper bounds checking in the Page State Change request handler to read and write memory outside the intended buffer boundaries. The attack allows the guest to leak sensitive information about the host kernel's memory layout and corrupt host kernel memory. The vulnerability requires the attacker to have already gained code execution within a virtual machine—it does not enable initial compromise of the host from an unprivileged network position.

  • CVE-2026-9910HIGH 8.8

    A memory safety bug in Google Chrome's graphics engine (ANGLE) allows an attacker to run malicious code within Chrome's sandbox by sending a specially crafted web page to a victim. The vulnerability requires user interaction—specifically visiting a malicious webpage—but no special privileges. Once triggered, an attacker could read sensitive data, modify browser state, or crash the application. This affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-9928HIGH 8.8

    A memory safety flaw in Google Chrome's ANGLE graphics library allows attackers to read data outside intended memory boundaries. When a user visits a specially crafted webpage, this out-of-bounds read can be weaponized to execute arbitrary code on the affected Windows system. The vulnerability affects Chrome versions prior to 148.0.7778.216 and is rated High severity by Chromium's security team.

  • CVE-2026-53230HIGH 8.7

    A memory safety flaw exists in the Linux kernel's Mellanox (mlx5) network driver. When querying MAC address lists from a virtual function (VF) with custom network configuration, the driver allocates a buffer that is too small, causing the firmware response to overflow the buffer boundary. This can lead to kernel crashes or potentially allow local privilege escalation. The fix involves reading the correct capacity limits from each virtual function's own configuration rather than assuming all functions match the physical function's limits.

  • CVE-2026-45607HIGH 8.4

    CVE-2026-45607 is a high-severity vulnerability in Windows Hyper-V that allows an attacker with local access to read memory outside intended boundaries and execute arbitrary code. The flaw requires no special privileges or user interaction to trigger, making it a direct path to system compromise on affected machines. This is not yet listed on the CISA Known Exploited Vulnerabilities catalog, but the combination of local access and code execution capability makes it a meaningful risk for organizations running Hyper-V infrastructure.

  • CVE-2026-45641HIGH 8.4

    CVE-2026-45641 is a type confusion vulnerability in Windows Hyper-V that allows an attacker with local system access to execute arbitrary code with full privileges. The flaw stems from the hypervisor incorrectly handling resource access when different data types are confused during processing, leading to memory corruption and code execution. This is a serious local privilege escalation vector affecting multiple Windows 10 and Windows 11 versions, as well as Windows Server 2022 and 2025.

  • CVE-2026-10017HIGH 8.3

    A memory read vulnerability exists in Google Chrome's Headless mode that could allow an attacker to escape the browser's security sandbox. If an attacker first compromises the renderer process—the part of Chrome that interprets web pages—they could craft a malicious HTML page to trigger an out-of-bounds read, potentially breaking out of the sandbox and gaining broader system access. This vulnerability requires the renderer to already be compromised, which is a significant precondition, but the consequence of successful exploitation is severe.

  • CVE-2026-10889HIGH 8.3

    A memory reading flaw in Chrome's ANGLE graphics library can let an attacker who has already gained control of the browser's rendering process break out of the Chrome sandbox and access the underlying system. The attack requires a specially crafted web page and user interaction, but once the renderer is compromised, this vulnerability opens a direct path to full system compromise. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10927HIGH 8.3

    A memory reading flaw in Google Chrome's graphics component (Dawn) prior to version 149.0.7827.53 allows attackers who have already compromised the browser's renderer process to escape the sandbox through a specially crafted webpage. This is a two-stage attack: first an attacker must find a way into the renderer, then this vulnerability allows them to break out entirely.

  • CVE-2026-11256HIGH 8.3

    CVE-2026-11256 is a sandbox escape vulnerability in Google Chrome's GPU processing that affects versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit an integer overflow in GPU code to break out of the browser sandbox and execute arbitrary code with higher privileges. The attack requires user interaction (visiting a malicious HTML page) and successful prior compromise of the renderer, making it a post-compromise escalation vector rather than a direct remote code execution path.

  • CVE-2026-46307HIGH 8.3

    CVE-2026-46307 is a memory safety bug in the Linux kernel's ath5k WiFi driver. The driver incorrectly writes data beyond the bounds of an array when handling wireless transmission status updates. While the out-of-bounds write itself is narrow in scope—it only affects an adjacent memory field used for signal strength reporting—the vulnerability demonstrates a real flaw that could be triggered during normal WiFi operations. An attacker with network proximity could potentially exploit this to corrupt driver state or trigger unexpected behavior.

  • CVE-2026-9889HIGH 8.3

    A memory safety vulnerability in Google Chrome's graphics rendering engine (Dawn) on Android devices allows an attacker to read and write memory outside intended boundaries. By crafting a malicious HTML page, a remote attacker could potentially escape the Chrome sandbox and gain elevated system privileges. This requires user interaction—the victim must visit the malicious page—but poses a critical threat to Android users.

  • CVE-2026-9895HIGH 8.3

    Google Chrome versions prior to 148.0.7778.216 contain an out-of-bounds read vulnerability in the GPU processing component. An attacker who has already compromised a renderer process can exploit this flaw by serving a specially crafted HTML page, potentially escaping the browser sandbox entirely. This is a critical chaining vulnerability—it requires prior renderer compromise but enables full system access.

  • CVE-2026-9975HIGH 8.3

    A memory safety vulnerability in Google Chrome's ANGLE graphics library allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain full system access. The flaw involves reading and writing memory beyond intended boundaries, creating a bridge from the restricted renderer environment to the host operating system. This requires the attacker to first successfully compromise the renderer (through a separate browser exploit or vulnerability) and then craft a malicious HTML page to trigger the escape.

  • CVE-2026-30802HIGH 8.2

    RTI Connext Micro, a real-time middleware platform used in distributed systems, contains a flaw that allows an attacker to read beyond the intended boundaries of a memory buffer. An unauthenticated attacker on the network can exploit this without user interaction to leak sensitive data from the application's memory or crash the service. The vulnerability affects Connext Micro versions from 4.0.0 up to (but not including) 4.3.0, and from 2.4.5 up to (but not including) 2.4.x where a patched version exists.

  • CVE-2026-44822HIGH 8.2

    Microsoft Office Excel contains an out-of-bounds read vulnerability that allows a remote attacker to extract sensitive information from a user's system without authentication or user interaction. The flaw affects multiple Microsoft Office products across different versions and deployment models. An attacker could exploit this by crafting a malicious Excel file or triggering the vulnerability over a network, potentially exposing confidential data.

  • CVE-2026-45615HIGH 8.2

    CVE-2026-45615 is a memory safety flaw in asn1c, an open-source ASN.1 compiler used to generate code that parses structured data formats. The vulnerability exists in the OER (Octet Encoding Rules) decoder template files generated by asn1c version 1.4 and earlier. When the generated decoder encounters a specially crafted, zero-length OER payload representing a variable-length non-negative integer, it attempts to read the Most Significant Bit without first validating that the payload contains sufficient bytes. This causes a precise one-byte out-of-bounds heap read. Since asn1c-generated parsers are commonly deployed to process untrusted network data—including automotive V2X protocols, 5G telecommunications headers, and X.509 certificates—a remote attacker can trigger this flaw by sending a malicious network message, potentially causing the application to crash or misinterpret critical security-relevant integers.

  • CVE-2026-52859HIGH 8.2

    Vim, a widely-used command-line text editor, contains a buffer overflow vulnerability in how it handles terminal output. When Vim displays terminal content with certain Unicode combining characters (accents, diacritics, etc.), a flaw in the snapshot function fails to safely copy the data, potentially reading past allocated memory. An attacker can craft terminal output that triggers this with just a few bytes, causing Vim to crash without requiring any user interaction or scripting. The vulnerability affects Vim versions prior to 9.2.0565.

  • CVE-2026-53268HIGH 8.2

    A flaw in the Linux kernel's netfilter IRC connection tracking module can cause the system to read memory beyond intended boundaries. When the module attempts to parse IRC protocol data and encounters a parsing failure after matching a command string, it fails to exit cleanly and instead tries to match additional commands, leading to out-of-bounds memory access. This can result in information disclosure or system crashes on affected Linux systems running the vulnerable netfilter code.

  • CVE-2026-54412HIGH 8.2

    A critical flaw in LiamBindle MQTT-C library versions through 1.1.6 allows remote attackers to crash MQTT clients and potentially leak sensitive memory. An attacker controlling or able to intercept traffic from an MQTT broker can send a specially crafted message that causes the client application to crash or expose data from adjacent memory regions. The vulnerability requires no authentication and can be triggered with a single malicious packet.

  • CVE-2026-54413HIGH 8.2

    A critical flaw in the driftregion iso14229 UDS (Unified Diagnostic Services) library versions through 0.9.0 allows an attacker to crash a diagnostic server and potentially read sensitive memory by sending a specially crafted single-byte request over automotive or industrial networks. The vulnerability exploits a missing validation check in the security access handler, causing the library to attempt reading far more data than is actually present in the input buffer. This affects vehicles, industrial controllers, and IoT devices that rely on this UDS implementation for diagnostic communication.

  • CVE-2026-57235HIGH 8.2

    Nokogiri, a widely-used Ruby library for parsing XML and HTML, contains an out-of-bounds read vulnerability in its NodeSet indexing method. When code calls the [] or slice method with a large negative index, the library's bounds check fails due to 32-bit truncation, allowing the operation to access memory outside the intended data structure. On standard Ruby (CRuby), this typically crashes the application; on JRuby, it silently returns incorrect data. The flaw affects all versions prior to 1.19.4.

  • CVE-2026-10930HIGH 8.1

    An out-of-bounds read vulnerability in ANGLE (the graphics translation layer used by Chrome on macOS) allows attackers to read sensitive memory from your system by tricking you into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.53 on Apple macOS. While the attacker cannot directly modify data or take control of your system through this specific vulnerability, they can extract confidential information—including passwords, encryption keys, or other sensitive data stored in memory—and cause Chrome to crash.

  • CVE-2026-11015HIGH 8.1

    A memory reading flaw in Google Chrome's WebGPU component allows attackers to read data outside the intended memory boundaries when a user visits a specially crafted website. The vulnerability requires user interaction (visiting a malicious page) but does not require special privileges, and while the attacker cannot modify data or directly crash the browser, they can extract sensitive information from the process's memory—such as passwords, keys, or other confidential data stored there.

  • CVE-2026-11111HIGH 8.1

    A memory reading vulnerability exists in Chrome's graphics engine (ANGLE) that allows attackers to access out-of-bounds data on a victim's system. An attacker could craft a malicious webpage that, when visited, leaks sensitive information from the browser's memory without modifying or corrupting system data. This affects Chrome versions prior to 149.0.7827.53. The vulnerability requires user interaction—a person must visit the malicious page—but once there, the attacker gains read access to protected memory regions.

  • CVE-2026-13819HIGH 8.1

    A memory-reading vulnerability exists in the ANGLE graphics library within Google Chrome on macOS versions prior to 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious web page to read data from outside the intended memory boundaries, potentially exposing sensitive information. The vulnerability requires the attacker to have already gained control of the renderer process, which typically happens after successful exploitation of another Chrome vulnerability.

  • CVE-2026-14011HIGH 8.1

    Google Chrome versions prior to 150.0.7871.47 contain an out-of-bounds read vulnerability in the SurfaceCapture component. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers an out-of-bounds memory read. While the Chromium team classified this as Medium severity internally, the CVSS 3.1 score of 8.1 reflects the high practical risk: an attacker gains unauthorized access to sensitive memory contents without requiring special privileges, and the vulnerability impacts both confidentiality and availability.

  • CVE-2026-14090HIGH 8.1

    A vulnerability in Google Chrome's camera capture feature fails to properly validate untrusted input, allowing an attacker to craft a malicious HTML page that triggers an out-of-bounds memory read. An unsuspecting user who visits the compromised page could have sensitive data extracted from Chrome's memory. This affects Chrome on ChromeOS versions before 150.0.7871.47. While Google rates this internally as low severity, the CVSS score reflects the realistic risk: high confidence of exploitation and access to confidential information.

  • CVE-2026-46138HIGH 8.1

    A flaw in the Linux kernel's Bluetooth event handler can cause the kernel to read memory beyond the bounds of a data structure and enter an infinite loop. The vulnerability occurs when a Bluetooth controller sends a specific event (LE_Create_BIG_Complete) with mismatched or insufficient data. An attacker with local or adjacent network access to a vulnerable system could exploit this to cause a denial of service by freezing the kernel with a lock held, making the system unresponsive.

  • CVE-2026-52967HIGH 8.1

    A memory safety flaw in the Linux kernel's SMB client code can cause the system to hang indefinitely or read sensitive data from memory when processing specially crafted symbolic link responses. The vulnerability affects 32-bit systems more directly, but the underlying logic issue exists in the code path. An attacker would need to trick a user into connecting to a malicious SMB server or intercept and modify SMB traffic to exploit this.

  • CVE-2026-53147HIGH 8.1

    A flaw in the Linux kernel's Thunderbolt XDomain protocol handler allows an attacker on the same network segment to crash a system or potentially read sensitive memory. When a Thunderbolt peer device sends a specially crafted packet, the kernel accepts it based on a generic header size check but then attempts to interpret the data as larger protocol-specific structures without verifying the packet is actually long enough. This mismatch causes the kernel to read beyond the packet boundary, potentially exposing kernel memory contents or triggering a system halt.

  • CVE-2026-53254HIGH 8.1

    A vulnerability in the Linux kernel's Bluetooth RFCOMM (Radio Frequency Communication) protocol handler allows a nearby attacker to read sensitive memory from a vulnerable device by sending specially crafted Bluetooth frames. The kernel fails to check the size of incoming data before processing it, leading to out-of-bounds memory reads. An attacker within Bluetooth range can exploit this without authentication to potentially leak confidential information or crash the system.

  • CVE-2026-8796HIGH 8.1

    Sereal::Decoder, a Perl serialization library, contains a heap memory safety flaw that allows attackers to read sensitive data from memory. By crafting malicious serialized input, an attacker can trick the decoder into reading beyond the intended buffer boundaries, potentially exposing heap memory contents. The vulnerability requires user interaction (such as processing an attacker-supplied file or message) but does not require special privileges and can be triggered remotely.

  • CVE-2025-41278HIGH 7.8

    A memory read vulnerability exists in Waterfall Security's WF-500 RX Host (version 7.10.0.0 R2601141040) that allows an attacker with access to the TX Host to execute arbitrary code. The flaw stems from improper memory access controls, enabling an authenticated insider to move laterally within the Waterfall appliance and gain control of the receive-side components. This is a serious concern for organizations using Waterfall's unidirectional security gateways, as it undermines the trust boundary between the TX and RX sides of the architecture.

  • CVE-2025-7002HIGH 7.8

    Avira Antivirus contains a vulnerability in its scanning engine that triggers when processing a specially crafted PDF file. The flaw allows an attacker to read data from memory locations outside the intended buffer, potentially leading to either arbitrary code execution on the infected system or a crash of the antivirus engine itself. This is a local attack—the malformed PDF must reach the scanner on a user's machine, typically via email, web download, or file share. The vulnerability affects Windows, macOS, and Linux installations running engine versions prior to 8.3.70.68.

  • CVE-2025-7003HIGH 7.8

    Avira Antivirus contains a flaw in its scanning engine that can crash or potentially allow code execution when it processes a specially crafted PDF file. The vulnerability exists in how the engine allocates and reads memory while parsing malformed PDF content. Any user on a Windows, macOS, or Linux system running an affected version of Avira could trigger this by opening or scanning a malicious PDF, even without administrator privileges. The issue affects all Avira Antivirus builds before version 8.3.70.56.

  • CVE-2025-7008HIGH 7.8

    Avast and its sister antivirus products (AVG, Norton, Avast One, and Avast Business) contain a memory safety flaw in their scanning engine that can be triggered by a specially crafted Windows executable file. When the antivirus scans such a file, it may read memory outside the intended buffer, potentially allowing an attacker with local access to execute code or crash the antivirus process itself. The vulnerability exists in the engine's handling of .NET metadata within PE files and is distributed across multiple consumer and business antivirus products via a shared Gen Digital virus definition update. The good news: updating virus definitions to build 25021310 or later eliminates the risk, regardless of which Gen Digital product you're running.

  • CVE-2025-7009HIGH 7.8

    A heap buffer overread vulnerability exists in Avast Antivirus and related products from Gen Digital. When the antivirus engine scans a specially crafted Windows PE file, it can read beyond allocated memory boundaries, potentially allowing an attacker with local access to crash the antivirus process or execute code with the privileges of the scanning service. The vulnerability is patched through automatic virus definition updates; users running the latest virus definition builds (VPS 25021310 and later) are protected regardless of product version.

  • CVE-2025-7011HIGH 7.8

    A heap memory error in antivirus software from Avast, AVG, Norton, and related Gen Digital products can cause the antivirus to crash or potentially execute code when scanning specially crafted zip files containing malformed XML. The vulnerability affects Windows, macOS, and Linux systems running older virus definition builds. Users are vulnerable only if their antivirus definitions are outdated; installing the patched definition build resolves the issue across all affected products that share this scanning engine.

  • CVE-2025-7017HIGH 7.8

    A flaw in Avira's antivirus scanning engine allows a specially crafted Windows installer (MSI) file to trigger a memory corruption issue. When scanned, this malformed file can crash the antivirus process or potentially enable an attacker to execute code with the privileges of the antivirus engine—typically system-level on Windows. The vulnerability requires user interaction (opening or scanning the malicious file) but no special privileges to exploit.

  • CVE-2025-9032HIGH 7.8

    Avira Antivirus contains a memory safety flaw that triggers when the scanning engine processes a specially crafted Windows executable file. An attacker who tricks a user into opening a malformed PE file can crash the antivirus process or potentially execute code with the privileges of the user running the scanner. The vulnerability affects Windows, macOS, and Linux systems running older Avira engine builds.

  • CVE-2025-9033HIGH 7.8

    Avira Antivirus contains a memory handling flaw that can be triggered when the engine scans a specially crafted PDF file. The vulnerability allows an attacker to either execute code on the system with the privileges of the scanning process or crash the antivirus engine, disabling its protection. This affects Windows, macOS, and Linux users running vulnerable versions of Avira Antivirus.

  • CVE-2026-0076HIGH 7.8

    CVE-2026-0076 is a local privilege escalation vulnerability in Android's ResourceTypes.cpp component. An attacker with local access to a device can trigger an out-of-bounds memory read through a flawed bounds check in the validateNode function. Successful exploitation allows the attacker to escalate privileges without requiring additional permissions or user interaction, potentially gaining elevated system access.

  • CVE-2026-0135HIGH 7.8

    CVE-2026-0135 is a buffer read vulnerability in Android's modem component that allows an attacker with local system access to execute arbitrary code without elevated privileges. The flaw stems from inadequate boundary checking when reading memory, potentially exposing sensitive data or enabling full system compromise. Exploitation requires no user action, making it a direct threat once an attacker gains initial foothold on a device.

  • CVE-2026-42837HIGH 7.8

    A flaw in Windows' Projected File System Filter Driver allows a local attacker with basic user permissions to read memory outside of intended boundaries and gain elevated system privileges. The vulnerability requires the attacker to already have local access to the machine—they cannot exploit it remotely over a network. This is a local privilege escalation risk affecting multiple versions of Windows 10, Windows 11, and Windows Server.

  • CVE-2026-44808HIGH 7.8

    A memory corruption flaw in Windows Desktop Window Manager (DWM) Core Library allows a user with local system access to escalate their privileges to a higher level of system access. The vulnerability stems from improper handling of memory buffers and requires an authenticated user to trigger, but does not require user interaction once triggered. This is a local privilege escalation vector that could allow an attacker with initial system access to gain administrative control.

  • CVE-2026-44820HIGH 7.8

    CVE-2026-44820 is a memory safety vulnerability in Microsoft Office Excel that allows an attacker to read memory outside the intended boundaries and execute arbitrary code. The attack requires local access to the machine and user interaction—typically opening a malicious file—but does not require elevated permissions. Once triggered, the attacker gains the same privileges as the user running Excel, making this a serious threat to any organization relying on Office for routine work.

  • CVE-2026-45258HIGH 7.8

    A memory validation flaw in FreeBSD's audio device driver allows unprivileged users to bypass security boundaries and access kernel memory. The `/dev/dsp` device—typically world-readable—permits any local user to exploit an integer overflow in the memory mapping validation logic, enabling them to read and modify kernel data, escalate privileges, or crash the system. The vulnerability exists because the kernel checks an arithmetic sum that can wrap around, making the overflow check unreliable.

  • CVE-2026-45457HIGH 7.8

    A flaw in Microsoft Office Word can allow an attacker to read memory outside the intended bounds and execute malicious code on a user's computer. The attack requires local access and user interaction—someone must open a specially crafted Word document. Once triggered, the vulnerability gives an attacker full control over the affected machine, including the ability to read sensitive data, modify files, or install malware.

  • CVE-2026-46260HIGH 7.8

    A memory safety defect in the Linux kernel's IPv6 routing code allows a local attacker with unprivileged user permissions to read data outside allocated memory boundaries. The vulnerability exists in the `fib6_add_rt2node()` function when processing IPv6 routes created with a specific routing attribute (RTA_NH_ID). Under certain conditions, the kernel reads from memory that doesn't belong to the expected data structure, potentially exposing sensitive kernel data or triggering a crash. The flaw requires local system access and cannot be exploited remotely.

  • CVE-2026-46263HIGH 7.8

    A bounds-checking flaw in the Linux kernel's AMD display driver can allow an unprivileged local user to read or write kernel memory. The vulnerability exists in the stream encoder initialization code, where an array index is not validated before use. When the engine ID parameter exceeds the valid range (0–4), the code accesses memory outside the intended array, potentially exposing sensitive kernel data or enabling privilege escalation.

  • CVE-2026-47333HIGH 7.8

    A memory safety flaw in Ubuntu Linux kernels 6.8, 6.17, and 7.0 allows unprivileged local users to read sensitive data from kernel memory. The vulnerability stems from incorrect buffer size calculation in AppArmor SAUCE patches, enabling out-of-bounds memory reads in the notification handling subsystem. An attacker can trigger this bug without administrative privileges and cause the AppArmor security policy engine to process invalid data, potentially exposing sensitive information or causing unexpected system behavior.

  • CVE-2026-52910HIGH 7.8

    A race condition exists in the Linux kernel's UDP socket handling code when multiple threads interact with Berkeley Packet Filter (BPF) programs attached to UDP socket groups. Specifically, when one thread replaces an attached BPF program while another thread is processing incoming UDP packets, the kernel may free the old BPF program prematurely without waiting for all packet-processing operations to complete. This can cause the packet processor to read from freed memory, leading to kernel crashes or potential code execution. The issue requires local access and unprivileged user-level code to trigger.

  • CVE-2026-52927HIGH 7.8

    A flaw in the Linux kernel's netfilter ebtables subsystem allows unprivileged local users to read memory beyond intended boundaries. The vulnerability stems from insufficient validation of user-supplied data structures when converting 32-bit ebtables extensions to kernel-native format. An attacker with local access can craft malformed extension data with undersized match or target structures, triggering out-of-bounds memory reads that leak kernel information or potentially crash the system.

  • CVE-2026-53078HIGH 7.8

    A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem allows unprivileged local users to leak kernel memory addresses and trigger out-of-bounds memory reads. The flaw exists in how the kernel handles certain BPF socket operations (sock_ops) when a program uses the same CPU register for both source and destination values. When specific network conditions occur—such as during TCP connection establishment with incomplete socket state—the kernel fails to properly clear the destination register, leaving sensitive kernel pointer data exposed. An attacker with local access can exploit this to bypass kernel address space layout randomization (ASLR) protections and read memory outside intended boundaries, potentially leading to privilege escalation or system compromise.

  • CVE-2026-53172HIGH 7.8

    A flaw in the Linux kernel's NPU (Neural Processing Unit) command stream parser allows a local attacker to corrupt kernel memory by sending specially crafted input. The vulnerability exists because the code incorrectly validates region indices for input feature map (IFM) regions, permitting values up to 127 when only 0–7 are valid. This mismatch enables an attacker to write data far beyond the intended memory buffer, potentially causing system instability, privilege escalation, or information disclosure.

  • CVE-2026-10817HIGH 7.5

    NetScaler ADC and NetScaler Gateway are vulnerable to a memory disclosure attack when TCP TimeStamp functionality is enabled on TCP profiles associated with load balancing, content switching, VPN virtual servers, or services. An attacker on the network can trigger insufficient input validation to read sensitive data from memory without requiring authentication or user interaction. The vulnerability exposes confidential information but does not allow system disruption or modification.

  • CVE-2026-11404HIGH 7.5

    Cesanta Mongoose, a popular embedded web server library, has a vulnerability in its built-in TLS implementation that allows an attacker to crash services remotely. When a client initiates a TLS connection, the server reads a length value from the client's handshake message but fails to verify it's reasonable before using it to read data from memory. An attacker can send a malformed TLS handshake with an inflated length value, causing the server to read beyond its buffer boundaries and crash. Any application using Mongoose's TLS server for HTTPS, MQTTS (MQTT over TLS), or WSS (WebSocket over TLS) services is at risk.

  • CVE-2026-11667HIGH 7.5

    Google Chrome versions prior to 149.0.7827.103 contain an out-of-bounds read vulnerability in WebRTC processing that could allow an attacker with prior access to the GPU process to corrupt heap memory and potentially execute code. The attack requires user interaction (clicking a malicious link or visiting a crafted webpage) but could lead to serious data theft or system compromise.

  • CVE-2026-11690HIGH 7.5

    A memory safety vulnerability in Google Chrome's media handling on macOS allows an attacker who has already compromised the browser's renderer process to read and write memory outside intended boundaries. By hosting a malicious HTML page, the attacker can exploit this flaw to execute arbitrary code even within Chrome's sandbox environment. The vulnerability affects Chrome versions prior to 149.0.7827.103 on macOS.

  • CVE-2026-12310HIGH 7.5

    A memory safety vulnerability was discovered in Firefox and Thunderbird that allows an attacker to read sensitive information from an affected system without requiring user interaction or special privileges. The flaw stems from improper memory handling in the browser engine and has been patched in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. No active exploitation has been reported to CISA as of this analysis.

  • CVE-2026-12314HIGH 7.5

    A memory safety vulnerability in Firefox and Thunderbird allows an attacker to read sensitive data from affected browsers without user interaction. The flaw stems from unsafe memory handling that permits out-of-bounds reads. An attacker on the network can exploit this remotely to compromise the confidentiality of user data—such as cached credentials, browsing history, or page content—without requiring the user to click a malicious link or perform any action. The vulnerability does not enable data modification or system crashes.

  • CVE-2026-12340HIGH 7.5

    A flaw in WolfSSL's SM2/SM3 certificate signature verification can cause the application to crash when processing specially crafted certificates. The vulnerability occurs because the code reads 65 bytes from a public key without first verifying the key is long enough, potentially accessing memory beyond allocated bounds. This affects only builds compiled with SM2 support enabled. There is no data corruption or information disclosure risk—the primary impact is denial of service through application crashes.

  • CVE-2026-34180HIGH 7.5

    OpenSSL contains a flaw in how it processes certain encoded certificate and data structures (ASN.1 format) that can cause applications to crash or read memory they shouldn't access. The vulnerability is triggered when an attacker crafts a specially formatted file with an unusually large size declaration—over 2 gigabytes—which confuses OpenSSL's decoder into reading beyond safe memory boundaries. This primarily affects server applications and services running on 64-bit Unix systems that directly process untrusted certificate or cryptographic data.

  • CVE-2026-38570HIGH 7.5

    CVE-2026-38570 is a denial-of-service vulnerability in bacnet_stack version 1.3.1 that stems from an out-of-bounds read flaw in the bacnet_tag_number_decode function. An attacker can trigger this flaw remotely without authentication to crash or hang systems running the vulnerable library, disrupting BACnet (Building Automation and Control Networks) operations. The vulnerability does not enable data theft or system compromise, but availability impact is significant in industrial and building automation environments where BACnet is critical infrastructure.

  • CVE-2026-39929HIGH 7.5

    Lakeside SysTrack Agent contains a vulnerability that allows an attacker on the network to crash the application by sending a malicious UDP packet. No authentication is required, and the attack does not require user interaction. The vulnerability affects multiple recent versions of the agent and results in denial of service, making it a significant availability risk for organizations relying on SysTrack for endpoint management and monitoring.

  • CVE-2026-40454HIGH 7.5

    Apache IoTDB's C++ client contains a flaw that causes it to crash when it receives malformed data from a server. An attacker positioned to intercept or manipulate server responses—or operating a malicious IoTDB instance—can send specially crafted messages that trigger an out-of-bounds memory read, crashing the client application. This is a denial-of-service vulnerability affecting IoTDB C++ clients in versions 1.3.5 through 1.3.7 and 2.0.5 through 2.0.9.

  • CVE-2026-42908HIGH 7.5

    A flaw in Windows Remote Desktop Protocol (RDP) allows an attacker on the network to read memory from the RDP service without authentication, potentially exposing sensitive information. The vulnerability requires no user interaction and can be exploited remotely by anyone with network access to an affected system running RDP. This is a confidentiality risk—the attacker cannot modify data or disrupt service, but unauthorized disclosure of system or user data is possible.

  • CVE-2026-45639HIGH 7.5

    A flaw in Windows Remote Desktop Protocol (RDP) allows attackers to read sensitive data from memory without authentication or user interaction. An attacker on the network could exploit this vulnerability to extract confidential information, though they cannot modify systems or cause outages. The vulnerability affects numerous Windows versions and related RDP clients.

  • CVE-2026-46133HIGH 7.5

    A flaw in the Linux kernel's RDMA/rxe (Soft RoCE) driver allows an unauthenticated attacker to crash the system by sending a specially crafted UDP packet with an invalid opcode. The vulnerability exists in how the driver validates incoming packets before processing checksums. When a packet uses an undefined opcode value, the driver fails to properly validate packet length, leading to an out-of-bounds memory read that triggers a kernel panic. An attacker needs only network access to the RDMA port and can exploit this without authentication, credentials, or any prior connection setup.

  • CVE-2026-48138HIGH 7.5

    A vulnerability in the NI grpc-device streaming API allows attackers to read memory beyond proper bounds, potentially causing the application to crash or become unavailable. The flaw stems from missing validation when processing specially crafted network requests. No authentication is required to trigger the issue, making it accessible to anyone with network access to affected systems.

  • CVE-2026-48502HIGH 7.5

    MessagePack for C# versions before 2.5.301 and 3.1.7 contain a critical memory management vulnerability in the timestamp parsing logic. When processing specially crafted MessagePack messages, the library allocates stack memory based on attacker-supplied values without first validating those values are legitimate. This can trigger a stack overflow that crashes the entire application with no opportunity for error handling. An attacker can exploit this remotely with a tiny payload to take down services using vulnerable versions of the library.

  • CVE-2026-49475HIGH 7.5

    FreeSWITCH, a popular open-source telecom platform used to build VoIP and communication systems, contains a flaw in how it processes STUN packets—a protocol used for network address translation and firewall traversal in voice communications. An attacker sending a specially crafted STUN packet with a mismatched attribute length can cause the software to read and write beyond allocated memory buffers. This out-of-bounds memory access occurs in the media buffer handling logic and can crash the affected FreeSWITCH instance, disrupting voice and video services. The vulnerability affects all versions prior to 1.11.0.

  • CVE-2026-52956HIGH 7.5

    A flaw in the Linux kernel's Ceph network communication library allows an attacker to read beyond the boundaries of a memory buffer when processing encrypted messages. An incoming message with insufficient data can cause the decryption function to access memory outside the buffer's allocated space, leading to a denial of service. This affects systems using Ceph for distributed storage or cluster communication.

  • CVE-2026-54341HIGH 7.5

    DragonflyDB, an in-memory data store, contains a vulnerability in how it processes RESTORE commands that can crash the entire server. An attacker without credentials can send a specially crafted command (roughly 24 bytes) to trigger this crash repeatedly. Because DragonflyDB runs without authentication by default, this is a straightforward remote denial-of-service attack. The issue affects all versions prior to 1.39.0 and is resolved in that release.

  • CVE-2026-54592HIGH 7.5

    Oj is a widely-used Ruby gem for parsing and marshalling JSON data. Versions before 3.17.3 contain a stack buffer overflow vulnerability triggered when the Oj::Doc#each_child method is called recursively on deeply nested JSON. The vulnerability stems from a missing bounds check and a missing restoration of an internal pointer (doc->where) during recursive traversal. An attacker can craft a malicious JSON document with excessive nesting depth to overflow a fixed 800-byte stack buffer, causing the Ruby process to crash. This results in a denial-of-service condition affecting any application using vulnerable Oj versions to parse untrusted JSON input.

  • CVE-2026-56017HIGH 7.5

    JavaScript::Minifier::XS, a Perl module used to compress JavaScript code, contains a critical flaw that causes immediate crashes when processing certain malformed input. Specifically, if the first substantive character in JavaScript code is a forward slash, the minifier's code reading logic attempts to access memory that doesn't exist, crashing the entire application. An attacker can exploit this by sending a single slash character to any service that uses this library to minify untrusted JavaScript, resulting in a denial of service attack. The vulnerability affects all versions before 0.16.

  • CVE-2026-5757HIGH 7.5

    A remote attacker can read sensitive data directly from an Ollama server's memory without needing to log in. The vulnerability exists in how Ollama processes model quantization requests, allowing an unauthenticated person on the network to extract heap memory contents. This could expose API keys, model weights, user data, or other confidential information stored in the server process, potentially enabling lateral movement or persistent backdoor installation.

  • CVE-2026-58469HIGH 7.5

    GNU Wget versions through 1.25.0 contain a memory safety flaw in how they process Metalink documents—a format used to describe downloadable files and mirrors. When a malicious server sends a Metalink file with a URL containing only whitespace characters, Wget's cleanup function reads memory outside its allocated buffer, potentially crashing the application or causing unpredictable behavior. An attacker controlling a server or intercepting traffic can exploit this by serving a specially crafted Metalink document to any Wget client that fetches from it.

  • CVE-2026-8451HIGH 7.5

    Citrix NetScaler ADC and NetScaler Gateway contain an input validation flaw that can cause the system to read beyond intended memory boundaries when configured to act as a SAML Identity Provider. An unauthenticated network attacker can exploit this condition to extract sensitive data from system memory, potentially including authentication tokens, encryption keys, or other confidential information. The vulnerability requires specific SAML IDP configuration but no user interaction.

  • CVE-2026-9076HIGH 7.5

    CVE-2026-9076 is a denial-of-service vulnerability in OpenSSL's CMS password-based decryption functionality. When processing specially crafted CMS messages, an attacker can trigger a heap buffer over-read that may crash the application. The vulnerability exists because OpenSSL's key unwrapping code assumes the cipher used for key encryption is block-based, but an attacker can specify a stream-mode cipher instead, bypassing length checks. No password knowledge is required to attempt the attack, and the vulnerability affects any application that decrypts untrusted CMS data using password-based key recovery. The FIPS modules are unaffected.

  • CVE-2026-0131HIGH 7.3

    A vulnerability in Android's RTP packet processing allows a local attacker to access memory outside intended boundaries, potentially escalating their privileges. The flaw stems from an integer overflow in the RtpPacket::decodePacket function. An attacker with basic local access can trigger the vulnerability if a user interacts with a malicious RTP stream—for example, by opening a crafted media file or accepting a call with specially prepared audio/video data.

  • CVE-2026-44185HIGH 7.3

    Apache HTTP Server contains a buffer over-read vulnerability triggered when the server makes outbound OCSP (Online Certificate Status Protocol) requests to an attacker-controlled server. An attacker can craft a malicious OCSP response that causes the HTTP Server to read beyond allocated memory boundaries, potentially exposing sensitive data or causing service disruption. All versions from 2.4.0 through 2.4.67 are affected; upgrading to version 2.4.68 resolves the issue.

  • CVE-2026-10658HIGH 7.1

    A buffer handling flaw in Zephyr's Bluetooth ISO receive path allows an attacker with access to an established Bluetooth connection to read and write memory beyond buffer boundaries. When processing incoming ISO data packets, the code fails to validate that the packet contains enough bytes before extracting header information. An attacker on a compromised or adjacent Bluetooth device can craft malicious packets to cause out-of-bounds reads that corrupt data structures, and in multi-packet scenarios, trigger out-of-bounds writes that overwrite critical memory regions. The vulnerability affects Zephyr versions 2.6.0 through 4.4.0 when Bluetooth ISO receive functionality is enabled (typically for LE Audio applications).

  • CVE-2026-13705HIGH 7.1

    Imager, a Perl image processing library, contains a memory safety flaw in its SGI image format parser. When processing specially crafted SGI files, the code miscalculates how many bytes to read from memory, causing it to read beyond the allocated buffer. This occurs only with 16-bit color SGI images and happens early enough in parsing that a malicious image can crash any application using Imager to open untrusted image files. The vulnerability requires user interaction (opening a file) but affects both local and remote scenarios where images are processed.

  • CVE-2026-45329HIGH 7.1

    CVE-2026-45329 is a memory disclosure vulnerability in Espressif's IoT Development Framework (ESP-IDF) affecting versions 5.5.4 and 6.0. The issue stems from inadequate input validation in secure-service wrapper functions that interface with TEE (Trusted Execution Environment) hardware. An attacker with local access can supply carefully crafted memory pointers to these wrappers, causing the underlying TEE-protected peripherals (such as ECC, SHA, or SPI engines) to read sensitive data from TEE-exclusive memory regions and return it to the untrusted realm. The disclosure occurs through direct byte leakage, computed results, or bit-level oracles, enabling incremental extraction of secrets stored in the TEE.

  • CVE-2026-46130HIGH 7.1

    A bug in the Linux kernel's dm-verity-fec (forward error correction) component can cause it to read data from outside the intended memory buffer. This occurs when parity bytes used to verify disk integrity are split across storage blocks in a specific way. Under certain non-default configurations and low-memory conditions, the code attempts to access more data than is available, leading to potential information disclosure or system instability. The issue only manifests with particular combinations of error correction parameters and buffer allocation scenarios.

  • CVE-2026-46140HIGH 7.1

    A flaw in the Linux kernel's Bluetooth driver (btmtk) fails to verify that incoming firmware responses contain sufficient data before reading from them. If a Bluetooth device sends a truncated or malformed response, the kernel code will read beyond the valid data boundaries, potentially exposing sensitive kernel memory. A local attacker with Bluetooth access could exploit this to leak information or crash the system.

  • CVE-2026-46190HIGH 7.1

    A memory access flaw exists in the Linux kernel's SPI NOR flash debugging code. When displaying flash chip parameters through the debugfs interface, the kernel incorrectly calculates the size of an internal lookup table, treating the table's byte-size instead of its element count. This can cause the kernel to read memory beyond the intended bounds when processing certain flag values. An unprivileged local user could exploit this to crash the system or potentially leak sensitive kernel memory.

  • CVE-2026-46191HIGH 7.1

    CVE-2026-46191 is a memory access vulnerability in the Linux kernel's framebuffer console (fbcon) subsystem. When the kernel attempts to rotate the console display and the memory reallocation fails, it continues using an undersized font buffer. If a user then prints characters with high numeric codes to the rotated console, the kernel will write beyond the buffer's boundaries, potentially corrupting kernel memory. An attacker with local system access can trigger this by printing specific characters after inducing a console rotation failure.