CWE-805: Buffer Access with Incorrect Length Value
The product uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer.
44 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-30651 — Junos OS and Junos OS Evolved: Receipt of a specific ICMPv6 packet causes a memory overrun leading to an rpd crash
- CVE-2025-20315 — A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau
- CVE-2024-37305 — Buffer overflow in deserialization in oqs-provider
- CVE-2025-23319 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
- CVE-2025-23318 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
- CVE-2025-38743 — Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnera
- CVE-2025-20169 — A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
- CVE-2026-12087 — Socket versions before 2.041 for Perl have an out-of-bounds heap read
- CVE-2024-24851 — A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of Automat
- CVE-2025-21591 — Junos OS: An unauthenticated adjacent attacker sending a malformed DHCP packet causes jdhcpd to crash
- CVE-2025-20202 — A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause
- CVE-2025-20191 — Multiple Cisco Products Denial of Service Vulnerability
- CVE-2025-36463 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36462 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36461 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36460 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2026-1837 — libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
- CVE-2025-20360 — Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerability
- CVE-2025-7048 — On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o
- CVE-2026-53877 — Heap buffer over-read in GDALRaster
Recently published
- CVE-2026-6695 — Gimp: gimp: remote code execution via crafted paa file
- CVE-2026-15028 — Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
- CVE-2026-53877 — Heap buffer over-read in GDALRaster
- CVE-2026-12549 — Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
- CVE-2026-1767 — Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tags
- CVE-2026-1766 — Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files.
- CVE-2026-12087 — Socket versions before 2.041 for Perl have an out-of-bounds heap read
- CVE-2026-34002 — Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling
- CVE-2026-6245 — Sssd: out-of-bounds read in the sssd
- CVE-2026-1837 — libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
- CVE-2026-0716 — Libsoup: out-of-bounds read in libsoup websocket frame processing
- CVE-2025-7048 — On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o
- CVE-2025-36463 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36462 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36461 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-36460 — Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability
- CVE-2025-20360 — Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerability
- CVE-2025-20315 — A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau
- CVE-2025-38743 — Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnera
- CVE-2025-23319 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
More specific weaknesses
- CWE-806 — Buffer Access Using Size of Source Buffer