VulnSea

CWE-129

CVEs classified under CWE-129, newest first.

61 CVEsRSS

CVE-2026-73489Medium· 4.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than 130 terminal-mode records. The parser in russh/src/server/encrypt…

▾ Sunlitrussh · russhEPSS 0.45%via NVD
CVE-2026-73564High
1mo ago

frp is a fast reverse proxy

frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF ma…

▾ Twilightfatedier · github.com/fatedier/frpEPSS 0.52%via NVD
CVE-2026-52856High· 7.5
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

▾ Twilightpterodactyl · github.com/pterodactyl/wingsEPSS 0.61%via NVD
CVE-2026-64330High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array i…

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array i…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64272High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and MMS136 The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes

In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and MMS136 The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes. When __mms114_rea…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
GHSA-26gq-p25f-99cpHigh
2mo ago

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

▾ Twilightfatedier · github.com/fatedier/frpvia GHSA
GHSA-cqjc-rmpq-xprqMedium· 4.3
2mo ago

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

▾ Sunlitrussh · russhvia GHSA
GHSA-3ccm-4qq2-5wrpMedium· 4.3
2mo ago

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
CVE-2026-22879High· 8.1
3mo ago

A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2)

A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. An attacker can provi…

▾ Twilightvtk · vtkEPSS 0.49%via NVD
CVE-2026-32682Medium· 6.5
3mo ago

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…

▾ Sunlitf5 · nginx_gateway_fabricEPSS 0.50%via NVD
CVE-2026-24181High· 7.3
3mo ago

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information d…

▾ Twilightnvidia · data_loading_libraryEPSS 0.14%via NVD
CVE-2026-45839High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that describe a path from a root BTF type to a …

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that describe a path from a root BTF type to a …

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-46598Medium· 5.3
4mo ago

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

▾ Sunlitx · golang.org/x/cryptoEPSS 0.52%via OSV
CVE-2026-6840Medium· 5.5
5mo ago

Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

▾ Sunlitsamsung · oneEPSS 0.15%via NVD
CVE-2026-33815High· 8.3
5mo ago

github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)

A flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.86%via CSAF
CVE-2026-33762Low· 2.8
6mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path n…

▾ Sunlitgo-git_project · go-gitEPSS 0.15%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-32286High· 7.5PoC
6mo ago

The DataRow.Decode function fails to properly validate field lengths

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

▾ Midnightjackc · pgproto3EPSS 0.92%via NVD
CVE-2026-3083High· 8.80day
6mo ago

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exp…

▾ Abyssalgstreamer · gstreamerEPSS 1.1%via NVD
CVE-2026-2006High· 8.8
7mo ago

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running…

▾ Twilightpostgresql · postgresqlEPSS 1.1%via NVD
CVE-2026-22859Critical· 9.1
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_ms…

▾ Midnightfreerdp · freerdpEPSS 0.87%via NVD
CVE-2022-49170High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on curseg->alloc_type As Wenqing Liu reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215657 - Overview UBSAN: array-in…

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on curseg->alloc_type As Wenqing Liu reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215657 - Overview UBSAN: array-in…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2022-48979High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix array index out of bound error in DCN32 DML [Why&How] LinkCapacitySupport array is indexed with the number of voltage states and not the number of…

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix array index out of bound error in DCN32 DML [Why&How] LinkCapacitySupport array is indexed with the number of voltage states and not the number of…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2024-42088High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-26699High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr [Why] There is a potential memory access violation while iterating through array of dcn35 clks. [How] L…

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr [Why] There is a potential memory access violation while iterating through array of dcn35 clks. [How] L…

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2023-52604High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Syzkaller reported the following issue: UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6 index 196694 …

In the Linux kernel, the following vulnerability has been resolved: FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Syzkaller reported the following issue: UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6 index 196694 …

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2023-52603High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 to 32768 UBSAN: array-index-out-of-boun…

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 to 32768 UBSAN: array-index-out-of-boun…

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CVE-2023-52599High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diNewExt [Syz report] UBSAN: array-index-out-of-bounds in fs/jfs/jfs_imap.c:2360:2 index -878706688 is out of range for type 'str…

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diNewExt [Syz report] UBSAN: array-index-out-of-bounds in fs/jfs/jfs_imap.c:2360:2 index -878706688 is out of range for type 'str…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2021-46984High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: kyber: fix out of bounds access when preempted __blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and passes the hctx to ->bio_merge()

In the Linux kernel, the following vulnerability has been resolved: kyber: fix out of bounds access when preempted __blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and passes the hctx to ->bio_merge(). kyber_bio_mer…

▾ Twilightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2023-2008High· 8.20dayPoC
3y ago

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allo…

▾ Abyssallinux · linux_kernelEPSS 1.0%via NVD
CWE-129 vulnerabilities (CVEs) — page 2 · VulnSea