CWE-193
CVEs classified under CWE-193, newest first.
29 CVEsRSS
CVE-2026-93018NoneImager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…
CVE-2026-76081Medium· 5.5ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…
CVE-2026-90781Medium· 4.4PoCalsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…
CVE-2026-81012Medium· 5.5⚖ disputedkernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (CVE-2026-81012)
A flaw was found in the Linux kernel's hp-bioscfg component. The `hp_get_string_from_buffer()` function contains an off-by-one write vulnerability. This occurs because the NUL terminator can be written one byte beyond the allocated buffer,…
CVE-2026-89751Medium· 4.7kernel: Linux kernel (x86/tdx): Off-by-one error in port I/O handling (CVE-2026-89751)
A flaw was found in the Linux kernel's x86/tdx component. An off-by-one error in the `handle_in()` and `handle_out()` functions, specifically in the `GENMASK` calculation for port I/O operations, causes the mask to be one bit too wide. Thi…
CVE-2026-81396High· 7.8Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-69609Medium· 5.5Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-86297High· 8.1PoCA vulnerability was identified in D-Link DIR-605 B1v202WWB03
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argumen…
CVE-2026-81738Low· 2.3OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
CVE-2026-57160Medium· 5.3⚖ disputedPJSIP is a free and open source multimedia communication library written in C
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic arr…
CVE-2026-17469Medium· 5.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
CVE-2026-85454Medium· 6.1MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-l…
CVE-2026-46369High· 7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative t…
CVE-2026-68767Medium· 6.1hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, po…
CVE-2026-63387High· 7.0PoCLibevent is an event notification library
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…
CVE-2026-55564Medium· 5.4FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malic…
CVE-2026-66806Medium· 5.5Microsoft Office Word Information Disclosure Vulnerability
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
GHSA-hwf3-r46v-5ggxLow· 2.9ImageMagick: Information Disclosure when printing profiles with debug enabled
ImageMagick: Information Disclosure when printing profiles with debug enabled
CVE-2026-50497Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-58380High· 7.3A flaw was found in GIMP's PNM file format parser
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the…
CVE-2026-58014High· 7.3PoCA flaw was found in GLib
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a deni…
CVE-2026-52804MediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-8357High· 7.8LibreOffice Calc compiles cell formulas when opening a spreadsheet
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small…
CVE-2026-54410High· 8.6nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…
nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…
CVE-2026-42015Medium· 5.3A flaw was found in gnutls
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains …
CVE-2026-43964Low· 3.7Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
CVE-2026-33997Medium· 6.8Moby is an open source container framework
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…
CVE-2025-47711Medium· 6.5There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, t…
CVE-2024-26766High· 7.8In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow. This reults …