VulnSea

CWE-130

CVEs classified under CWE-130, newest first.

27 CVEsRSS

CVE-2023-5778High· 7.5
4d ago

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controll…

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controll…

TwilightABB · Freelance Controller DCPEPSS 0.29%via NVD
CVE-2026-73455High· 7.5
6d ago

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

TwilightArista Networks · EOSEPSS 0.48%via NVD
CVE-2026-90678High· 7.5
1w ago

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic…

TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.52%via NVD
CVE-2026-89613Medium· 5.5⚖ disputed
1w ago

kernel: ntfs: reject invalid empty mapping pairs (CVE-2026-89613)

A flaw was found in the Linux kernel's NTFS filesystem driver. This vulnerability occurs when the driver processes an attribute with empty mapping pairs that have inconsistent highest Virtual Cluster Number (VCN) and size. A local attacker…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89480High· 7.0
1w ago

kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)

A flaw was found in the NVMe-TCP implementation of the Linux kernel. This vulnerability occurs when the system completes a data read request even if the connected controller transfers fewer bytes than expected. As a result, the user applic…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.41%via CSAF
CVE-2026-89586Medium· 5.5⚖ disputed
1w ago

kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (CVE-2026-89586)

A flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due …

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-15418Low· 2.4
1w ago

CP210x Memory Leakage

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Window…

SunlitSilicon Labs · silabser.sys driverEPSS 0.15%via CVEORG
CVE-2026-71337High· 7.8
2w ago

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_21h2EPSS 0.31%via NVD
CVE-2026-84947Low· 3.7⚖ disputed
2w ago

undici's dump interceptor reads and discards a response body up to a configurable maximum size

undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length…

Sunlitnodejs · undiciEPSS 0.20%via NVD
CVE-2026-5706None
3w ago

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network…

SunlitEPSS 0.27%via NVD
CVE-2026-80213Medium· 4.0
3w ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but t…

SunlitRuby · resolvEPSS 0.35%via NVD
CVE-2026-58097High· 7.8
3w ago

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…

Twilightfreebsd · freebsdEPSS 0.22%via NVD
CVE-2026-58096High· 8.8
3w ago

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095…

Twilightfreebsd · freebsdEPSS 0.56%via NVD
CVE-2026-67292Medium· 6.5
1mo ago

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c)

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed t…

Sunlitfreerdp · freerdpEPSS 0.33%via NVD
CVE-2026-54466Critical
2mo ago

websocket-driver: Message corruption via abuse of protocol length headers

websocket-driver: Message corruption via abuse of protocol length headers

Midnightwebsocket-driver · websocket-driverEPSS 0.22%via GHSA
CVE-2026-48487Medium· 6.5
3mo ago

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

Sunlitzeroconf · zeroconfEPSS 0.25%via GHSA
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.37%via NVD
CVE-2026-42216Critical· 9.1PoC
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…

Abyssalopenexr · openexrEPSS 0.46%via NVD
CVE-2026-43125Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXL…

Midnightlinux · linux_kernelEPSS 0.43%via NVD
CVE-2026-33846High· 7.5
4mo ago

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type,…

TwilightRed Hat · gnutlsEPSS 1.3%via NVD
CVE-2026-5367High· 8.6
5mo ago

A flaw was found in OVN (Open Virtual Network)

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond …

TwilightEPSS 0.87%via NVD
CVE-2026-41898Medium· 5.3
5mo ago

rust-openssl provides OpenSSL bindings for the Rust programming language

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_sta…

Sunlitrust-openssl_project · rust-opensslEPSS 0.28%via NVD
CVE-2026-41035High· 7.4
5mo ago

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configuratio…

Twilightsamba · rsyncEPSS 0.39%via NVD
CVE-2026-33555Medium· 4.0PoC
5mo ago

An issue was discovered in HAProxy before 3.3.6

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause des…

Twilighthaproxy · haproxyEPSS 0.30%via NVD
CVE-2025-48956High· 7.5
1y ago

vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests (CVE-2025-48956)

A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…

TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.56%via CSAF
CVE-2021-36374Medium· 5.5
5y ago

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using…

Sunlitapache · antEPSS 2.6%via NVD
CVE-2021-36373Medium· 5.5
5y ago

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Ap…

Sunlitapache · antEPSS 2.5%via NVD
CWE-130 vulnerabilities (CVEs) · VulnSea