VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-53465Medium· 6.2
3mo ago

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.16%via GHSA
CVE-2026-48994Medium· 5.9
3mo ago

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-2050High· 7.80day
3mo ago

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

▾ Abyssalgimp · gimpEPSS 0.61%via NVD
CVE-2026-12725Medium· 5.9
3mo ago

A heap-based buffer overflow was found in dnsmasq

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an …

▾ Sunlitredhat · openshift_container_platformEPSS 0.53%via NVD
CVE-2026-56208High· 7.6
3mo ago

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when …

▾ TwilightRed Hat · firefoxEPSS 0.42%via NVD
CVE-2026-54896High
3mo ago

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-2467High· 8.1
3mo ago

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.…

▾ Twilightrti · connext_professionalEPSS 0.19%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

▾ Midnightf5 · dosEPSS 2.4%via NVD
CVE-2026-0130Medium· 4.3
3mo ago

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita…

▾ Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-52720High· 8.8
3mo ago

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client)

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that exte…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-48914Medium· 6.7
3mo ago

A flaw was found in QEMU's virtio-blk device

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by su…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-11604Medium· 6.5
3mo ago

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted dat…

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted dat…

▾ Sunlitopenvpn · ovpn-dco-winEPSS 0.34%via NVD
CVE-2026-24180High· 7.3
3mo ago

NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow

NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information d…

▾ Twilightnvidia · data_loading_libraryEPSS 0.16%via NVD
CVE-2026-45475High· 7.8
3mo ago

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.57%via CVEORG
CVE-2026-41108High· 7.0
3mo ago

Windows DNS Client Elevation of Privilege Vulnerability

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-45469High· 7.8
3mo ago

Microsoft Excel Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-40404High· 7.8
3mo ago

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-44819High· 7.8
3mo ago

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.57%via CVEORG
CVE-2026-44824High· 7.8
3mo ago

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.57%via CVEORG
CVE-2026-45466Low· 3.3
3mo ago

Microsoft Word Information Disclosure Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45657Critical· 9.8
3mo ago

Windows Kernel Remote Code Execution Vulnerability

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 11 version 23H2EPSS 0.97%via CVEORG
CVE-2026-47291Critical· 9.8
3mo ago

HTTP.sys Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.97%via CVEORG
CVE-2026-47289High· 8.8
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-47635High· 8.4
3mo ago

Microsoft Outlook and Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft Office LTSC 2024EPSS 0.36%via CVEORG
CVE-2026-47652High· 8.2
3mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.35%via CVEORG
CVE-2026-45636High· 7.8
3mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-45638High· 7.8
3mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-45653High· 7.0
3mo ago

Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-48574High· 7.8
3mo ago

Windows Media Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-42904Critical· 9.6
3mo ago

Windows TCP/IP Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

▾ MidnightMicrosoft · Windows 10 Version 21H2EPSS 0.53%via CVEORG
CWE-122 vulnerabilities (CVEs) — page 25 · VulnSea