最近六个月的全部 CVE,每天更新。
直接来自 National Vulnerability Database 的已公开漏洞,附带严重程度、CWE 类别和受影响产品。可搜索、可筛选,今天新增的也能马上看到。
- 过去 24 小时 254 条
- 过去 7 天 2,855 条
- 过去六个月 58,248 条
来源:NVD(National Vulnerability Database) · 更新于 2026年9月23日
显示 114 条中的 100 条
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versio
Transient DOS while parsing frame during channel usage.
Information Disclosure when a pointer is reused after being deallocated.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local ac
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration i
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end o
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CWE-126mozilla thunderbirdlibvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enla
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CWE-126wireshark wiresharkERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CWE-126wireshark wiresharkOut-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versi
CWE-126postgresql postgresqlBuffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.
CWE-126postgresql postgresqlBuffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CWE-126microsoft edge_chromiumBuffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
CWE-126apache thriftxrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capabi
CWE-126neutrinolabs xrdpProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which resu
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message,
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null term
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CWE-126microsoft windows_subsystem_for_linuxBuffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CWE-126microsoft sql_server_2025Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can caus
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across t
CWE-126gnu gzipAn out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.co
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CWE-126qualcomm 5g_fixed_wireless_access_platform_firmwarequalcomm 5g_fixed_wireless_access_platformqualcomm ar8035_firmwareA flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major ve
CWE-126postgresql postgresqlCrypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len i
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Transient DOS when processing target power rate tables during channel configuration.
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CWE-126apache http_serverAGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, yielding values 0-15.
CWE-126linuxfoundation automotive_grade_linuxKismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CWE-126wireshark wiresharkThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow
CWE-126gnu glibcrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_c
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console out
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f932952
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byt
CWE-126wolfssl wolfssl