VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-21357High· 7.8
7mo ago

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…

▾ Twilightadobe · indesignEPSS 0.23%via NVD
CVE-2026-25646High· 8.1
7mo ago

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API functio…

▾ Twilightlibpng · libpngEPSS 0.64%via NVD
CVE-2025-62673High· 8.0
7mo ago

Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…

Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…

▾ Twilighttp-link · archer_ax53_firmwareEPSS 0.55%via NVD
CVE-2025-15059High· 7.80day
8mo ago

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

▾ Abyssalgimp · gimpEPSS 0.85%via NVD
CVE-2026-23876High· 8.1
8mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to w…

▾ Twilightimagemagick · imagemagickEPSS 0.66%via NVD
CVE-2026-23534Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destin…

▾ Midnightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-23533Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes out-of-bounds writes d…

▾ Midnightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-23532Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clam…

▾ Midnightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-23531Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, …

▾ Midnightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-23530Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious …

▾ Midnightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2025-25249High· 8.1CISA KEVPoC
8mo ago

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

▾ Abyssalfortinet · fortiswitchmanagerEPSS 3.9%via NVD
CVE-2026-21304High· 7.8
8mo ago

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…

▾ Twilightadobe · indesignEPSS 0.27%via NVD
CVE-2026-21283High· 7.8
8mo ago

Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

▾ Twilightadobe · bridgeEPSS 0.29%via NVD
CVE-2026-21281High· 7.8
8mo ago

InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

▾ Twilightadobe · incopyEPSS 0.22%via NVD
CVE-2026-21277High· 7.8
8mo ago

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…

▾ Twilightadobe · indesignEPSS 0.27%via NVD
CVE-2026-20922High· 7.8
8mo ago

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-20876Medium· 6.7
8mo ago

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

▾ Sunlitmicrosoft · windows_11_23h2EPSS 0.52%via NVD
CVE-2026-20868High· 8.8
8mo ago

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.4%via NVD
CVE-2026-20864High· 7.8
8mo ago

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.56%via NVD
CVE-2026-20840High· 7.8
8mo ago

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 4.7%via NVD
CVE-2026-20837High· 7.8
8mo ago

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.69%via NVD
CVE-2026-20820High· 7.8PoC
8mo ago

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 2.6%via NVD
CVE-2026-20809High· 7.8
8mo ago

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.36%via NVD
CVE-2025-67268Critical· 9.8
8mo ago

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the…

▾ Midnightgpsd_project · gpsdEPSS 0.77%via NVD
CVE-2025-10881High· 7.8
9mo ago

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…

▾ Twilightautodesk · shared_componentsEPSS 0.28%via NVD
CVE-2025-11788Critical· 9.8
10mo ago

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(me…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.33%via NVD
CVE-2025-7983High· 7.80day
1y ago

Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User intera…

▾ Abyssalashlar · graphiteEPSS 0.22%via NVD
CVE-2025-34523Critical· 9.8
1y ago

A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP)

A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when proce…

▾ Midnightarcserve · udpEPSS 0.53%via NVD
CVE-2025-34522Critical· 9.8
1y ago

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP)

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper b…

▾ Midnightarcserve · udpEPSS 0.56%via NVD
CVE-2025-32990Medium· 6.5
1y ago

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OO…

▾ Sunlitgnu · gnutlsEPSS 0.79%via NVD
CWE-122 vulnerabilities (CVEs) — page 28 · VulnSea