VulnSea

CWE-120

CVEs classified under CWE-120, newest first.

251 CVEsRSS

CVE-2026-92020High· 8.8
6d ago

Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component

Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, …

TwilightMozilla · FirefoxEPSS 0.28%via NVD
CVE-2026-92043High· 8.8⚖ disputed
6d ago

Privilege escalation due to incorrect boundary conditions in the Audio/Video component

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-84632High· 7.3
1w ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a mali…

Twilightapple · ipadosEPSS 0.13%via NVD
CVE-2026-28934Medium· 6.5
1w ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.

Sunlitapple · macosEPSS 0.34%via NVD
CVE-2026-84520Critical· 9.8
1w ago

A buffer overflow was addressed with improved size validation

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.

Midnightapple · macosEPSS 0.33%via NVD
CVE-2026-84577High· 8.2
1w ago

An access issue was addressed with additional sandbox restrictions

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to bypass sandbox restrictions.

Twilightapple · macosEPSS 0.13%via NVD
CVE-2026-84609Critical· 9.8
1w ago

A permissions issue was addressed with improved path validation

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to modify prot…

Midnightapple · ipadosEPSS 0.61%via NVD
CVE-2026-84497High· 7.8
1w ago

A buffer overflow was addressed with improved size validation

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously…

Twilightapple · ipadosEPSS 0.18%via NVD
CVE-2026-84571Medium· 4.3
1w ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termina…

Sunlitapple · ipadosEPSS 0.39%via NVD
CVE-2026-65357High· 7.8
1w ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel m…

Twilightapple · ipadosEPSS 0.13%via NVD
CVE-2026-65398High· 7.8
1w ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or …

Twilightapple · ipadosEPSS 0.13%via NVD
CVE-2026-84512High· 8.8
1w ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrup…

Twilightapple · macosEPSS 0.46%via NVD
CVE-2026-84489Medium· 5.5
1w ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a de…

Sunlitapple · ipadosEPSS 0.17%via NVD
CVE-2026-84581High· 8.4
1w ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrup…

Twilightapple · macosEPSS 0.20%via NVD
CVE-2026-90804Medium· 4.8PoC
1w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument…

Twilightgnu · binutilsEPSS 0.14%via NVD
CVE-2026-90803Medium· 5.3PoC
1w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads …

Twilightgnu · binutilsEPSS 0.14%via NVD
CVE-2026-90801Medium· 5.3PoC
1w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local…

Twilightgnu · binutilsEPSS 0.16%via NVD
CVE-2026-90608Critical· 9.9PoC
1w ago

A flaw has been found in Totolink A3002MU Hh-B20211125.1046

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It i…

AbyssalTotolink · A3002MUEPSS 0.80%via NVD
CVE-2026-90606Critical· 9.9PoC
1w ago

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to…

AbyssalTotolink · A3002MUEPSS 0.49%via NVD
CVE-2026-90605Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to bu…

AbyssalTotolink · A3002MUEPSS 0.47%via NVD
CVE-2024-53922Medium· 5.7
1w ago

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.

SunlitSamsung · Exynos 8890 firmwareEPSS 0.16%via NVD
CVE-2026-90607Critical· 9.9PoC
1w ago

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow…

AbyssalTotolink · A3002MUEPSS 0.47%via NVD
CVE-2025-64031Low· 2.5PoC⚖ disputed
1w ago

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…

Twilightlibarchive · libarchiveEPSS 0.12%via NVD
CVE-2023-24291Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24287Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24285Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24284Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2026-82772High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec EC1000 series

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

TwilightContec Co., Ltd. · ECE1000EPSS 0.46%via NVD
CVE-2026-82770High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

TwilightContec Co., Ltd. · RP-WAH-SR1EPSS 0.46%via NVD
CVE-2026-16726Medium· 6.8
1w ago

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

Sunlitpanasonic · PANATERM v6EPSS 0.11%via NVD
CWE-120 vulnerabilities (CVEs) — page 2 · VulnSea