VulnSea

CWE-193

CVEs classified under CWE-193, newest first.

29 CVEsRSS

CVE-2026-93018None
4d ago

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…

SunlitEPSS 0.18%via NVD
CVE-2026-76081Medium· 5.5
1w ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…

Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.23%via NVD
CVE-2026-90781Medium· 4.4PoC
1w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

TwilightALSA Project · alsa-libEPSS 0.18%via NVD
CVE-2026-81012Medium· 5.5⚖ disputed
1w ago

kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (CVE-2026-81012)

A flaw was found in the Linux kernel's hp-bioscfg component. The `hp_get_string_from_buffer()` function contains an off-by-one write vulnerability. This occurs because the NUL terminator can be written one byte beyond the allocated buffer,…

SunlitRed Hat · LinuxEPSS 0.14%via CSAF
CVE-2026-89751Medium· 4.7
1w ago

kernel: Linux kernel (x86/tdx): Off-by-one error in port I/O handling (CVE-2026-89751)

A flaw was found in the Linux kernel's x86/tdx component. An off-by-one error in the `handle_in()` and `handle_out()` functions, specifically in the `GENMASK` calculation for port I/O operations, causes the mask to be one bit too wide. Thi…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-81396High· 7.8
2w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Twilightmicrosoft · 365_appsEPSS 0.42%via NVD
CVE-2026-69609Medium· 5.5
2w ago

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.39%via NVD
CVE-2026-86297High· 8.1PoC
2w ago

A vulnerability was identified in D-Link DIR-605 B1v202WWB03

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argumen…

MidnightD-Link · DIR-605EPSS 1.0%via NVD
CVE-2026-81738Low· 2.3
2w ago

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

SunlitOpenVPN · OpenVPNEPSS 0.33%via NVD
CVE-2026-57160Medium· 5.3⚖ disputed
2w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic arr…

Sunlitteluu · pjsipEPSS 0.31%via NVD
CVE-2026-17469Medium· 5.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

Sunlitibm · iEPSS 0.21%via NVD
CVE-2026-85454Medium· 6.1
2w ago

MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer

MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-l…

Sunlitthemoos · core-moosEPSS 0.22%via NVD
CVE-2026-46369High· 7.5
3w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative t…

Twilightnimiq-blockchain · nimiq-blockchainEPSS 0.39%via NVD
CVE-2026-68767Medium· 6.1
1mo ago

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, po…

SunlitEPSS 0.13%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

Midnightlibevent · libeventEPSS 0.42%via NVD
CVE-2026-55564Medium· 5.4
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malic…

SunlitEPSS 0.33%via NVD
CVE-2026-66806Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.31%via CVEORG
GHSA-hwf3-r46v-5ggxLow· 2.9
2mo ago

ImageMagick: Information Disclosure when printing profiles with debug enabled

ImageMagick: Information Disclosure when printing profiles with debug enabled

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-50497Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58380High· 7.3
2mo ago

A flaw was found in GIMP's PNM file format parser

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the…

Twilightgimp · gimpEPSS 0.26%via NVD
CVE-2026-58014High· 7.3PoC
2mo ago

A flaw was found in GLib

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a deni…

Midnightgnome · glibEPSS 0.41%via NVD
CVE-2026-52804Medium
3mo ago

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Sunlitgogs · gogs.io/gogsEPSS 0.50%via GHSA
CVE-2026-8357High· 7.8
3mo ago

LibreOffice Calc compiles cell formulas when opening a spreadsheet

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small…

TwilightEPSS 0.22%via NVD
CVE-2026-54410High· 8.6
3mo ago

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

TwilightEPSS 0.54%via NVD
CVE-2026-42015Medium· 5.3
3mo ago

A flaw was found in gnutls

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains …

SunlitEPSS 0.73%via NVD
CVE-2026-43964Low· 3.7
4mo ago

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Sunlitpostfix · postfixEPSS 0.51%via NVD
CVE-2026-33997Medium· 6.8
5mo ago

Moby is an open source container framework

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…

Sunlitdocker · engineEPSS 0.39%via NVD
CVE-2025-47711Medium· 6.5
1y ago

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, t…

Sunlitnbdkit_project · nbdkitEPSS 0.45%via NVD
CVE-2024-26766High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow. This reults …

Twilightlinux · linux_kernelEPSS 0.27%via NVD
CWE-193 vulnerabilities (CVEs) · VulnSea