VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

346 CVEsRSS

CVE-2026-94030Low· 3.1
yesterday

A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c

A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cp…

SunlitEPSS 0.47%via NVD
CVE-2026-61723Medium· 6.8
3d ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication …

SunlitFluidSynth · fluidsynthEPSS 0.14%via NVD
CVE-2026-61722Medium· 6.8
3d ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that …

SunlitFluidSynth · fluidsynthEPSS 0.15%via NVD
CVE-2026-57226Low· 3.7
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompre…

SunlitOISF · suricataEPSS 0.55%via NVD
CVE-2026-11725High· 8.8
3d ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

TwilightIBM · MQEPSS 0.40%via NVD
CVE-2026-46655High· 7.8
3d ago

virtio-win provides Windows paravirtualized drivers for QEMU and KVM

virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*]…

Twilightvirtio-win · kvm-guest-drivers-windowsEPSS 0.12%via NVD
CVE-2026-84449Low· 3.7
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

Sunlitstrukturag · libheifEPSS 0.34%via NVD
CVE-2026-65969Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is proce…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.13%via NVD
CVE-2026-11378High· 8.8
3d ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

TwilightIBM · MQEPSS 0.59%via NVD
CVE-2026-93652High· 7.5
3d ago

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

TwilightD3TN GmbH · µD3TNEPSS 0.32%via NVD
CVE-2026-40531Medium· 4.3
3d ago

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

SunlitSynology · DiskStation Manager (DSM)EPSS 0.33%via NVD
CVE-2026-93313Medium· 6.3PoC
3d ago

A vulnerability was found in Freedesktop Poppler 26.07.0

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be ini…

TwilightFreedesktop · PopplerEPSS 0.25%via NVD
CVE-2026-93314Medium· 6.3
3d ago

A vulnerability was determined in Freedesktop Poppler 26.07.0

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attac…

SunlitFreedesktop · PopplerEPSS 0.25%via NVD
CVE-2026-93311Medium· 4.3
3d ago

A vulnerability was detected in Freedesktop Poppler 26.07.0

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSampl…

SunlitFreedesktop · PopplerEPSS 0.32%via NVD
CVE-2026-54571High· 8.7
4d ago

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMu…

TwilightESP32Async · ESPAsyncWebServerEPSS 0.30%via NVD
CVE-2026-25290High· 7.8
4d ago

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.11%via NVD
CVE-2026-63126High· 7.5PoC
5d ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary b…

Midnightsquare · wireEPSS 0.68%via NVD
CVE-2026-77408Critical· 9.1
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

Midnightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77406High· 8.2
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-19667High· 7.5
5d ago

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This iss…

TwilightISC · BIND 9EPSS 0.49%via NVD
CVE-2026-89775Critical· 9.3
5d ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached b…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached b…

MidnightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-92248High· 7.8
6d ago

A flaw was found in the file-psd plugin in GIMP

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header…

TwilightGNOME · gimpEPSS 0.18%via NVD
CVE-2026-92259Medium· 5.5
6d ago

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

SunlitSamsung Opensource · EscargotEPSS 0.17%via NVD
CVE-2026-91746Medium· 4.3⚖ disputed
6d ago

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91728Critical· 9.6
6d ago

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-0194High· 8.4
6d ago

In multiple locations, there is a possible permission bypass due to an integer overflow

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-55351High· 7.8
6d ago

In VPU, there is a possible out-of-bounds write due to an integer overflow

In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-56889Medium· 6.7
6d ago

In multiple locations, there is a possible permission bypass due to an integer overflow

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-91960Medium· 6.5PoC
6d ago

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a cra…

TwilightFreeRDP · FreeRDPEPSS 0.44%via NVD
CVE-2026-84487Medium· 6.5
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Proces…

Sunlitapple · ipadosEPSS 0.36%via NVD
CWE-190 vulnerabilities (CVEs) · VulnSea