CVE-2026-69303
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
CVSS
5.5
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-125 · CWE-191
Sin historial EPSS suficiente todavía.
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-877958.2 ALT—
——0zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.3hCVE-2026-877364.3 MED—
——0An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.8hCVE-2026-816465.9 MED—
——0Out-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.9hCVE-2026-493147.3 ALT—
——0OOB write vulnerability in the rendering and composition module.
Impact: Successful exploitation of this vulnerability may affect availability.9hCVE-2026-87650——
——0Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)13hCVE-2026-87640——
——0Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)13h