VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-91088Medium· 4.8PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be …

▾ TwilightEPSS 0.16%via NVD
CVE-2026-91086Medium· 6.3PoC
1w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based …

▾ TwilightEPSS 0.55%via NVD
CVE-2026-84510Medium· 6.5
1w ago

A heap buffer overflow was addressed with improved bounds checking

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume …

▾ Sunlitapple · ipadosEPSS 0.45%via NVD
CVE-2026-86870Medium· 6.5
1w ago

A heap buffer overflow was addressed with improved bounds checking

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to u…

▾ Sunlitapple · ipadosEPSS 0.45%via NVD
CVE-2026-19499High· 7.7
1w ago

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

▾ TwilightThe GNU C Library · glibcEPSS 0.30%via NVD
CVE-2025-64031Low· 2.5PoC⚖ disputed
1w ago

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…

▾ Twilightlibarchive · libarchiveEPSS 0.18%via NVD
CVE-2026-90682Medium· 5.3PoC
1w ago

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG …

▾ TwilightMatthias-Wandel · jheadEPSS 0.17%via NVD
CVE-2026-23788Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.

▾ SunlitSamsung · Exynos 1280 firmwareEPSS 0.10%via NVD
CVE-2026-54559Medium· 6.9
1w ago

PocketSphinx is a small speech recognizer

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loader…

▾ Sunlitcmusphinx · pocketsphinxEPSS 0.55%via NVD
CVE-2026-90577Medium· 5.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffe…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-90556High· 7.8
2w ago

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files th…

▾ Twilightfreeciv · freecivEPSS 0.20%via NVD
CVE-2026-54241High· 7.4
2w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and …

▾ Twilightstrukturag · libde265EPSS 0.39%via NVD
CVE-2026-18495Medium· 6.1
2w ago

A flaw was found in libtiff

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causin…

▾ SunlitRed Hat · libtiff-mainEPSS 0.12%via NVD
CVE-2026-79393High· 7.5
2w ago

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to ca…

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to ca…

▾ TwilightEPSS 0.74%via NVD
CVE-2026-45761Low· 3.3
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow w…

▾ Sunlitoisf · suricataEPSS 0.18%via NVD
CVE-2026-79591High· 7.8PoC
2w ago

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

▾ MidnightEPSS 0.17%via NVD
CVE-2026-42807High· 8.0
2w ago

A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code.…

A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code.…

▾ TwilightBosch Sensortec · COINES_SDKEPSS 0.31%via NVD
CVE-2026-21095Critical· 9.8
2w ago

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

▾ Midnightsamsung · androidEPSS 0.46%via NVD
CVE-2026-21096Critical· 9.8
2w ago

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

▾ Midnightsamsung · androidEPSS 0.46%via NVD
CVE-2026-21104Medium· 6.7
2w ago

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

▾ Sunlitsamsung · androidEPSS 0.10%via NVD
CVE-2026-85103Critical· 9.8
2w ago

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

▾ Midnightcheckpoint · Quantum Security GatewayEPSS 3.7%via NVD
CVE-2026-87527Critical· 9.6
2w ago

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-87654Critical· 9.6
2w ago

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-87579High· 8.8
2w ago

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.57%via NVD
CVE-2026-87430High· 8.8⚖ disputed
2w ago

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.57%via NVD
CVE-2026-53938High· 8.2
2w ago

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) do…

▾ TwilightOpenIDC · cjoseEPSS 0.39%via NVD
GHSA-mqvm-gmc4-6rv2High· 8.8
2w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
GHSA-4qhr-qf46-fcrxHigh· 8.8
2w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

▾ TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
GHSA-rgj7-g3m4-5g8cHigh
2w ago

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

▾ Twilightsharp · sharpvia GHSA
CVE-2026-81993Medium· 5.5
2w ago

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requi…

▾ Sunlitadobe · acrobatEPSS 0.30%via NVD
CWE-122 vulnerabilities (CVEs) — page 3 · VulnSea