VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

387 CVEsRSS

CVE-2026-37198High· 7.5
1mo ago

An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.

An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.

▾ TwilightEPSS 0.63%via NVD
CVE-2026-47857Medium· 5.9
1mo ago

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and ea…

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and ea…

▾ Sunlitbroadcom · reactor_coreEPSS 0.37%via NVD
CVE-2025-70293Critical· 9.8
1mo ago

An issue was discovered in Denx U-Boot before 2026.04

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() wh…

▾ MidnightEPSS 0.82%via NVD
CVE-2025-70290Critical· 9.8
1mo ago

An issue was discovered in Denx U-Boot before 2026.04

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-59982High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds po…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.42%via NVD
CVE-2026-59186High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a …

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.41%via NVD
CVE-2026-59183Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication i…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-55373Medium· 6.2
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. Th…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-54920None· 0.0
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-52491High· 8.4
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.19%via NVD
CVE-2026-18445Medium· 6.6
1mo ago

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to ge…

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to ge…

▾ Sunlitni · labviewEPSS 0.13%via NVD
CVE-2022-50998High· 7.5
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ TwilightRed HatEPSS 0.35%via NVD
CVE-2026-52492High· 7.8
1mo ago

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF…

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF…

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.19%via NVD
CVE-2026-77219High· 7.1
1mo ago

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image load…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-50278Medium· 6.5
1mo ago

iccDEV provides a set of libraries and tools for working with ICC color management profiles

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing I…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-72852High· 7.8PoC
1mo ago

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c …

▾ Midnighthank-ai · darknetEPSS 0.21%via NVD
CVE-2026-72854Medium· 5.3PoC
1mo ago

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubli…

▾ Twilightmsgpack · msgpack-cEPSS 0.16%via NVD
CVE-2026-69242None
1mo ago

libvips is a fast image processing library with low memory needs

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overf…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-18917High· 7.8
1mo ago

A flaw was found in libvirt

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. …

▾ TwilightRed Hat · libvirtEPSS 0.18%via NVD
CVE-2026-63384High· 7.5
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.52%via NVD
CVE-2026-69419High· 8.5
1mo ago

Azure Data Manager for Energy Remote Code Execution Vulnerability

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Azure Data Manager for EnergyEPSS 0.74%via CVEORG
CVE-2026-61799Medium· 5.3
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-75148Medium· 6.1
1mo ago

cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote attackers to cause memory disclosure and denial of service by supplying crafted accessor cou…

cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote attackers to cause memory disclosure and denial of service by supplying crafted accessor cou…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-68552Medium· 5.3
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len va…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-55191Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c wit…

▾ Midnightfreerdp · freerdpEPSS 0.83%via NVD
CVE-2026-16933High· 8.2
1mo ago

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in th…

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in th…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-16661High· 8.2
1mo ago

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-l…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-55648High· 7.5⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-b…

▾ Twilightfreerdp · freerdpEPSS 0.43%via NVD
CVE-2026-52834High· 7.3
1mo ago

jxl-oxide is a pure Rust implementation of a JPEG XL decoder

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…

▾ Twilightjxl-grid · jxl-gridEPSS 0.17%via NVD
CVE-2026-50161Critical· 9.8
1mo ago

libre is a generic library for real-time communications with asynchronous input and output support

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket fr…

▾ MidnightRed HatEPSS 0.52%via NVD
CWE-190 vulnerabilities (CVEs) — page 6 · VulnSea