VulnSea

CWE-120

CVEs classified under CWE-120, newest first.

283 CVEsRSS

CVE-2026-0157Medium· 4.3
3mo ago

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.17%via NVD
CVE-2026-0165Medium· 6.5
3mo ago

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0155Medium· 5.3
3mo ago

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploit…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0144High· 7.5
3mo ago

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed fo…

▾ Twilightgoogle · androidEPSS 0.27%via NVD
CVE-2026-0141Medium· 5.3
3mo ago

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl…

▾ Sunlitgoogle · androidEPSS 0.21%via NVD
CVE-2026-0136High· 7.5
3mo ago

In Modem, there is a possible out of bounds read due to a missing bounds check

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.27%via NVD
CVE-2026-0129Medium· 4.3
3mo ago

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-12328High· 8.1
3mo ago

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c…

▾ Twilightmozilla · firefoxEPSS 0.48%via NVD
CVE-2026-54257Critical
3mo ago

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

▾ Midnightelectron · electronEPSS 0.43%via GHSA
CVE-2026-49759High· 8.2
3mo ago

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/c…

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/c…

▾ Twilighterlang · erlang/otpEPSS 0.86%via NVD
CVE-2026-9698Critical· 9.8
3mo ago

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that c…

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that c…

▾ Midnightperl · dbiEPSS 0.82%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

▾ Midnightapache · http_serverEPSS 2.7%via NVD
CVE-2026-34355High· 7.5
3mo ago

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

▾ Twilightapache · http_serverEPSS 2.7%via NVD
CVE-2026-30652High· 8.8
3mo ago

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbi…

▾ Twilightvivotek · fd8136_firmwareEPSS 0.76%via NVD
CVE-2018-25426High· 7.5
4mo ago

WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters

WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers can create a specially crafted input fi…

▾ Twilightwinmtr · winmtrEPSS 0.51%via NVD
CVE-2018-25423Medium· 6.2
4mo ago

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input …

▾ SunlitEPSS 0.14%via NVD
CVE-2026-6477High· 8.8
4mo ago

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-l…

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-l…

▾ Twilightpostgresql · postgresqlEPSS 0.45%via NVD
CVE-2026-40067High· 7.5
4mo ago

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-43658High· 7.5
4mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted…

▾ Twilightapple · ipadosEPSS 0.54%via NVD
CVE-2026-8260High· 8.8
4mo ago

A vulnerability was found in D-Link DCS-935L up to 1.10.01

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword r…

▾ Twilightdlink · dcs-935l_firmwareEPSS 1.2%via NVD
CVE-2026-42311High· 7.8
4mo ago

Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing (CVE-2026-42311)

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the app…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-34956Medium· 5.9
4mo ago

A flaw was found in Open vSwitch

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characte…

▾ SunlitEPSS 0.64%via NVD
CVE-2025-50673High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

▾ Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50672High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

▾ Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50670High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, a…

▾ Twilightdlink · di-8003_firmwareEPSS 0.49%via NVD
CVE-2025-50669High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

▾ Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50668High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.

▾ Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50667High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.

▾ Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50666High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parame…

▾ Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CVE-2025-50665High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the n…

▾ Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CWE-120 vulnerabilities (CVEs) — page 6 · VulnSea