Search Results (11071 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-98188 1 Linux 1 Linux Kernel 2026-10-09 5.5 Medium
In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate curve data length in the calibration curve converters p54_convert_rev0() and p54_convert_rev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54_convert_output_limits() and p54_convert_db() already validate their counts against the entry length; this path was missed. Reject the entry when the counts do not fit in the entry data.
CVE-2026-106061 1 Redhat 1 Enterprise Linux 2026-10-09 5.5 Medium
A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap, after integer overflow in the size calculation. This can crash GIMP or corrupt process memory.
CVE-2026-105775 1 Vllm-project 1 Vllm 2026-10-09 4.3 Medium
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-107729 1 Sumatrapdfreader 1 Sumatrapdf 2026-10-08 5.5 Medium
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, src/MobiDoc.cpp narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation; values above INT_MAX become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. Opening a crafted MOBI file can reliably terminate the application with a native access violation; no code execution, information disclosure, or integrity impact has been demonstrated. No fixed version is available as of this review.
CVE-2026-107731 1 Sumatrapdfreader 1 Sumatrapdf 2026-10-08 5.5 Medium
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. The affected calculations include contentOffset, the directory expression dirOff64 + dirLen64, and the decoded-section offset + size, along with secondary-header range handling. Opening a crafted LIT file that reaches one of these variants can cause invalid pointer reads and deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
CVE-2026-107738 1 Sumatrapdfreader 1 Sumatrapdf 2026-10-08 N/A
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, ChmFile::GetCharZ() narrows file-controlled unsigned string offsets from /#WINDOWS and /#IVB to signed integers without a lower-bound check. An offset that becomes negative can make the function read before the /#STRINGS buffer, causing deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
CVE-2016-9840 9 Apple, Boost, Canonical and 6 more 27 Iphone Os, Mac Os X, Tvos and 24 more 2026-10-08 8.8 High
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2026-106428 1 Mongodb 1 C Driver 2026-10-08 3.7 Low
An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.
CVE-2026-106435 1 Mongodb 1 Python Driver 2026-10-08 5.1 Medium
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
CVE-2022-2287 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.1 High
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVE-2022-2286 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVE-2022-2206 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-2183 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-2175 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVE-2022-2126 4 Apple, Debian, Fedoraproject and 1 more 4 Macos, Debian Linux, Fedora and 1 more 2026-10-08 7.8 High
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-2124 4 Apple, Debian, Fedoraproject and 1 more 4 Macos, Debian Linux, Fedora and 1 more 2026-10-08 7.8 High
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVE-2021-4166 7 Apple, Debian, Fedoraproject and 4 more 8 Mac Os X, Macos, Debian Linux and 5 more 2026-10-08 7.1 High
vim is vulnerable to Out-of-bounds Read
CVE-2021-40158 1 Autodesk 11 Advance Steel, Autocad, Autocad Architecture and 8 more 2026-10-08 7.8 High
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2021-20193 1 Gnu 1 Tar 2026-10-08 3.3 Low
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
CVE-2020-28097 2 Linux, Netapp 18 Linux Kernel, Cloud Backup, H300e and 15 more 2026-10-08 5.9 Medium
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.