VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-58534High· 8.8
2mo ago

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-58530High· 7.8
2mo ago

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.36%via CVEORG
CVE-2026-58547Medium· 5.5
2mo ago

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.41%via CVEORG
CVE-2026-58542High· 7.8
2mo ago

Windows Media Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.36%via CVEORG
CVE-2026-50696High· 7.5
2mo ago

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1809EPSS 1.2%via NVD
CVE-2026-57094High· 8.8
2mo ago

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-57090High· 8.8
2mo ago

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-57087High· 8.8
2mo ago

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.79%via NVD
CVE-2026-56650High· 7.8
2mo ago

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-58640High· 7.3
2mo ago

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.36%via NVD
CVE-2026-49800High· 7.8
2mo ago

Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.33%via NVD
CVE-2026-49164High· 8.1
2mo ago

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.79%via NVD
CVE-2026-48564High· 8.8
2mo ago

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.91%via NVD
CVE-2026-42990Critical· 9.8
2mo ago

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-42975High· 8.0
2mo ago

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-15520Medium· 5.3
2mo ago

A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035

A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-base…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-15506High· 7.8
2mo ago

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An a…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-56372Low· 3.3
2mo ago

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially expos…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-57156None
2mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlle…

▾ SunlitEPSS 0.70%via NVD
CVE-2026-54000None
2mo ago

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes t…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-15028Low· 3.9
2mo ago

A flaw was found in libarchive

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.…

▾ SunlitRed Hat · libarchiveEPSS 0.20%via NVD
CVE-2026-56002High· 8.5
2mo ago

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

▾ Twilightx · libxfontEPSS 0.56%via NVD
CVE-2026-56645High· 8.8
2mo ago

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.82%via NVD
CVE-2026-14610Medium· 5.3
2mo ago

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes h…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-14355Medium· 5.6
2mo ago

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-w…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-58379High· 7.3
2mo ago

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a special…

▾ TwilightEPSS 0.33%via NVD
CVE-2025-10997High· 7.8
2mo ago

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

▾ Twilightopenbabel · openbabelEPSS 0.28%via GHSA
CVE-2022-46289High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser

Open Babel has out-of-bounds write in ORCA nAtoms parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46290High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2026-12912High· 7.3
3mo ago

A flaw was found in libtiff

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR outp…

▾ TwilightRed Hat · libtiffEPSS 0.43%via NVD
CWE-122 vulnerabilities (CVEs) — page 24 · VulnSea