VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

387 CVEsRSS

CVE-2026-93313Medium· 6.3PoC
1w ago

A vulnerability was found in Freedesktop Poppler 26.07.0

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be ini…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-93314Medium· 6.3PoC
1w ago

A vulnerability was determined in Freedesktop Poppler 26.07.0

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attac…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-93311Medium· 4.3PoC
1w ago

A vulnerability was detected in Freedesktop Poppler 26.07.0

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSampl…

▾ TwilightFreedesktop · PopplerEPSS 0.56%via NVD
CVE-2026-54571High· 8.7
1w ago

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMu…

▾ TwilightESP32Async · ESPAsyncWebServerEPSS 0.52%via NVD
CVE-2026-25290High· 7.8
1w ago

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-63126High· 7.5PoC
1w ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary b…

▾ Midnightsquare · wireEPSS 0.82%via NVD
CVE-2026-77408Critical· 9.1
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77406High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-19667High· 7.5
1w ago

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This iss…

▾ TwilightISC · BIND 9EPSS 0.55%via NVD
CVE-2026-89775Critical· 9.3
1w ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached b…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached b…

▾ MidnightLinux · LinuxEPSS 0.23%via NVD
CVE-2026-92248High· 7.8
1w ago

A flaw was found in the file-psd plugin in GIMP

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header…

▾ TwilightGNOME · gimpEPSS 0.21%via NVD
CVE-2026-92259Medium· 5.5
1w ago

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

▾ SunlitSamsung Opensource · EscargotEPSS 0.14%via NVD
CVE-2026-91746Medium· 4.3⚖ disputed
1w ago

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91728Critical· 9.6
1w ago

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-76685High· 8.1
1w ago

A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input

A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially …

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.67%via NVD
CVE-2026-0194High· 8.4
1w ago

In multiple locations, there is a possible permission bypass due to an integer overflow

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-55351High· 7.8
1w ago

In VPU, there is a possible out-of-bounds write due to an integer overflow

In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-56889Medium· 6.7
1w ago

In multiple locations, there is a possible permission bypass due to an integer overflow

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-91960Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a cra…

▾ Twilightfreerdp · freerdpEPSS 0.46%via NVD
CVE-2026-84487Medium· 6.5
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Proces…

▾ Sunlitapple · ipadosEPSS 0.46%via NVD
CVE-2026-84517Medium· 5.5
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-65390High· 8.8
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may le…

▾ Twilightapple · safariEPSS 0.41%via NVD
CVE-2026-65391High· 8.8
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web conten…

▾ Twilightapple · safariEPSS 0.41%via NVD
CVE-2026-84536Medium· 6.5
1w ago

An integer underflow was addressed with improved input validation

An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.

▾ Sunlitapple · macosEPSS 0.40%via NVD
CVE-2026-84544High· 7.5
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt …

▾ Twilightapple · macosEPSS 0.57%via NVD
CVE-2026-84548High· 7.1
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted document may lead to an out-of-bounds read.

▾ Twilightapple · macosEPSS 0.17%via NVD
CVE-2026-84620High· 7.3
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Proces…

▾ Twilightapple · ipadosEPSS 0.17%via NVD
CVE-2026-43788Medium· 6.6
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-65408Medium· 5.5
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected s…

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-84554Medium· 5.9
1w ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.

▾ Sunlitapple · macosEPSS 0.49%via NVD
CWE-190 vulnerabilities (CVEs) — page 2 · VulnSea