VulnSea

CWE-131

CVEs classified under CWE-131, newest first.

45 CVEsRSS

CVE-2026-8357High· 7.8
3mo ago

LibreOffice Calc compiles cell formulas when opening a spreadsheet

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-11604Medium· 6.5
3mo ago

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted dat…

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted dat…

▾ Sunlitopenvpn · ovpn-dco-winEPSS 0.34%via NVD
CVE-2026-42915Medium· 5.5
3mo ago

Microsoft Windows VMSwitch Denial of Service Vulnerability

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.40%via CVEORG
CVE-2026-44420High· 8.8
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a t…

▾ Twilightfreerdp · freerdpEPSS 0.85%via NVD
CVE-2026-43501Critical· 9.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

▾ Abyssallinux · linux_kernelEPSS 0.99%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-40618High· 7.5
4mo ago

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed…

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.43%via NVD
CVE-2026-41676High· 7.5
5mo ago

rust-openssl provides OpenSSL bindings for the Rust programming language

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on Ope…

▾ Twilightrust-openssl_project · rust-opensslEPSS 0.46%via NVD
CVE-2026-41989High· 7.5
5mo ago

Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989)

A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentia…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 8)EPSS 0.19%via CSAF
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

▾ Midnightcryptography.io · cryptographyEPSS 0.76%via NVD
CVE-2026-34986High· 7.5
5mo ago

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and …

▾ Twilightgo-jose_project · go-joseEPSS 0.76%via NVD
CVE-2026-34743Medium· 5.3
5mo ago

XZ Utils provide a general-purpose data-compression library plus command-line tools

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state wher…

▾ Sunlittukaani · xzEPSS 0.57%via NVD
CVE-2025-61661Medium· 4.8
10mo ago

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit incons…

▾ SunlitEPSS 0.19%via NVD
CVE-2023-1175Medium· 6.6
3y ago

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

▾ Sunlitneovim · neovimEPSS 0.45%via NVD
CWE-131 vulnerabilities (CVEs) — page 2 · VulnSea