VulnSea

CWE-131

CVEs classified under CWE-131, newest first.

38 CVEsRSS

CVE-2026-84448Medium· 4.0
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals…

Sunlitstrukturag · libheifEPSS 0.12%via NVD
CVE-2026-67549High· 7.6
4d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so cal…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.26%via NVD
CVE-2026-54692High· 7.8PoC
5d ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using t…

MidnightHappySeaFox · sailEPSS 0.14%via NVD
CVE-2026-91962Medium· 6.3
1w ago

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer s…

SunlitFreeRDP · FreeRDPEPSS 0.24%via NVD
CVE-2026-89538High· 7.0⚖ disputed
1w ago

kernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field (CVE-2026-89538)

A flaw was found in the Linux kernel's Server Unix Remote Procedure Call (SUNRPC) component. A remote attacker, with a valid Generic Security Service (GSS) context, could send a specially crafted Kerberos v2 wrap token with an oversized "e…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.70%via CSAF
CVE-2026-89608Medium· 5.5
1w ago

kernel: ecryptfs: pass packet set buffer size to parser (CVE-2026-89608)

A flaw was found in the `ecryptfs` component of the Linux kernel. The `ecryptfs_parse_packet_set()` function incorrectly calculates the available buffer size when processing version 1 headers, leading to an overstatement of the buffer's ac…

SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.16%via CSAF
CVE-2026-89718Medium· 5.5
1w ago

In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store() Patch series "zram: fix stale scan bounds after reinitialization". Both writeback_store() and read_block_state() d…

In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store() Patch series "zram: fix stale scan bounds after reinitialization". Both writeback_store() and read_block_state() d…

SunlitLinux · LinuxEPSS 0.15%via NVD
CVE-2026-47773High· 7.2
1w ago

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt mem…

Twilightarduino-libraries · ArduinoBLEEPSS 0.10%via NVD
CVE-2026-22590Critical· 9.1PoC
1w ago

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group)

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read whil…

AbyssaleProsima · Fast-DDSEPSS 0.38%via NVD
CVE-2026-69598High· 8.8
2w ago

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.84%via NVD
CVE-2026-78221Medium· 5.9
2w ago

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

SunlitOpenVPN · OpenVPNEPSS 0.12%via NVD
CVE-2026-18743Low· 2.5
3w ago

A flaw was found in popt

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `po…

Sunlitrpm-software-management · poptEPSS 0.14%via NVD
CVE-2026-78002High· 7.5
3w ago

A flaw was found in rsyslog

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer …

TwilightRed Hat · rsyslogEPSS 0.61%via NVD
CVE-2026-44254Medium· 5.3
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG()…

Sunlitwazuh · wazuhEPSS 0.38%via NVD
CVE-2026-52834High· 7.3
1mo ago

jxl-oxide is a pure Rust implementation of a JPEG XL decoder

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…

Twilightjxl-grid · jxl-gridEPSS 0.13%via NVD
CVE-2026-42170High· 7.8
1mo ago

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an u…

TwilightEPSS 0.16%via NVD
CVE-2026-71430Medium· 6.2
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that…

SunlitRed Hat · re2EPSS 0.15%via NVD
CVE-2026-54696Low· 3.7
2mo ago

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Sunlitjson · jsonEPSS 0.38%via GHSA
CVE-2026-53366High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as allocl…

In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as allocl…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.39%via CSAF
CVE-2026-55827High· 7.5
2mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while al…

TwilightEPSS 0.34%via NVD
CVE-2026-0280High· 7.2
2mo ago

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach …

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach …

Twilightpaloaltonetworks · pan-osEPSS 0.34%via NVD
GHSA-66m8-c62j-h6v5Medium· 6.2
2mo ago

jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow

jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow

Sunlitjxl-oxide · jxl-oxidevia GHSA
CVE-2026-53209High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum extended advertising payload

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum extended advertising payload. When hci…

Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-2050High· 7.80day
3mo ago

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

Abyssalgimp · gimpEPSS 0.61%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

Midnightf5 · dosEPSS 6.5%via NVD
CVE-2026-8357High· 7.8
3mo ago

LibreOffice Calc compiles cell formulas when opening a spreadsheet

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small…

TwilightEPSS 0.22%via NVD
CVE-2026-44420High· 8.8
3mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a t…

Twilightfreerdp · freerdpEPSS 3.7%via NVD
CVE-2026-43501Critical· 9.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

Abyssallinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

Midnightf5 · dosEPSS 68%via NVD
CWE-131 vulnerabilities (CVEs) · VulnSea