Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-34251 | 1 Bytecodealliance | 1 Webassembly Micro Runtime | 2025-06-13 | N/A | 7.5 HIGH |
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |||||
CVE-2025-5918 | 2025-06-12 | N/A | 3.9 LOW | ||
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition. | |||||
CVE-2025-33063 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-32719 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33058 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-32715 | 2025-06-12 | N/A | 6.5 MEDIUM | ||
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |||||
CVE-2025-33062 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-32716 | 2025-06-12 | N/A | 7.8 HIGH | ||
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. | |||||
CVE-2025-24065 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-24069 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33055 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33061 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33059 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33060 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-33065 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-32720 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | |||||
CVE-2025-47112 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2025-49133 | 2025-06-12 | N/A | 5.9 MEDIUM | ||
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1. | |||||
CVE-2023-22113 | 2 Netapp, Oracle | 2 Oncommand Insight, Mysql | 2025-06-12 | N/A | 2.7 LOW |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). | |||||
CVE-2024-22251 | 2 Apple, Vmware | 3 Macos, Fusion, Workstation | 2025-06-10 | N/A | 5.9 MEDIUM |
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure. |