VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-57164Medium· 5.9⚖ disputed
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applic…

▾ Sunlitteluu · pjsipEPSS 0.45%via NVD
CVE-2026-18341Medium· 6.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

▾ Sunlitibm · iEPSS 0.25%via NVD
CVE-2026-83959High· 7.8
3w ago

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must …

▾ Twilightadobe · substance_3d_samplerEPSS 0.34%via NVD
CVE-2026-53720Medium
3w ago

pymonocypher uses cython to wrap the Monocypher C library

pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, t…

▾ Sunlitpymonocypher · pymonocypherEPSS 0.18%via NVD
CVE-2026-75538High· 8.2
3w ago

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond …

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond …

▾ TwilightErlang · otpEPSS 0.85%via NVD
CVE-2026-38821High· 7.1
1mo ago

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code executio…

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code executio…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-38347High· 7.5
1mo ago

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-19313Critical· 9.3
1mo ago

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ MidnightWatchGuard · Fireware OSEPSS 0.47%via NVD
CVE-2026-58097High· 7.8
1mo ago

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…

▾ Twilightfreebsd · freebsdEPSS 0.17%via NVD
CVE-2026-58095High· 8.8
1mo ago

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…

▾ Twilightfreebsd · freebsdEPSS 0.60%via NVD
CVE-2025-70293Critical· 9.8
1mo ago

An issue was discovered in Denx U-Boot before 2026.04

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() wh…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-68515High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.19%via NVD
CVE-2026-68514Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap …

▾ SunlitEPSS 0.18%via NVD
CVE-2026-59187High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write w…

▾ TwilightRed HatEPSS 0.40%via NVD
CVE-2026-59186High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a …

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.41%via NVD
CVE-2026-39113Medium· 4.0PoC
1mo ago

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11…

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-68513High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered …

▾ TwilightRed HatEPSS 0.19%via NVD
CVE-2026-56135High· 7.4
1mo ago

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS i…

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS i…

▾ TwilightEPSS 0.14%via NVD
CVE-2026-19874Critical· 9.1PoC
1mo ago

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers u…

▾ AbyssalEPSS 0.92%via NVD
CVE-2026-62381Medium· 6.6
1mo ago

luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key

luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is compute…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-55893None
1mo ago

Capstone is a disassembly framework

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-70654None
1mo ago

libvips is a fast image processing library with low memory needs

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in v…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-70653None
1mo ago

libvips is a fast image processing library with low memory needs

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old a…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-69242None
1mo ago

libvips is a fast image processing library with low memory needs

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overf…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-76022High· 8.8
1mo ago

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ TwilightEPSS 0.45%via NVD
CVE-2026-76883Medium· 4.7PoC
1mo ago

Heap-based Buffer Overflow in Wireshark

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76889Medium· 4.7
1mo ago

Heap-based Buffer Overflow in Wireshark

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76887Low· 3.1
1mo ago

Heap-based Buffer Overflow in Wireshark

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.31%via CVEORG
CVE-2026-76888Low· 3.1PoC
1mo ago

Heap-based Buffer Overflow in Wireshark

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.33%via CVEORG
CVE-2026-76917Medium· 5.5
1mo ago

Heap-based Buffer Overflow in Wireshark

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CWE-122 vulnerabilities (CVEs) — page 15 · VulnSea