最近六个月的全部 CVE,每天更新。
直接来自 National Vulnerability Database 的已公开漏洞,附带严重程度、CWE 类别和受影响产品。可搜索、可筛选,今天新增的也能马上看到。
- 过去 24 小时 362 条
- 过去 7 天 2,933 条
- 过去六个月 58,248 条
来源:NVD(National Vulnerability Database) · 更新于 2026年9月23日
显示 114 条中的 50 条
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versio
Transient DOS while parsing frame during channel usage.
Information Disclosure when a pointer is reused after being deallocated.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local ac
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration i
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end o
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CWE-126mozilla thunderbirdlibvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enla
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CWE-126wireshark wiresharkERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CWE-126wireshark wiresharkOut-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versi
CWE-126postgresql postgresqlBuffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.
CWE-126postgresql postgresqlBuffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CWE-126microsoft edge_chromium