VulnSea

CWE-197

CVEs classified under CWE-197, newest first.

30 CVEsRSS

CVE-2026-63449Low· 3.7
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fie…

SunlitOISF · suricataEPSS 0.24%via NVD
CVE-2026-19667High· 7.5
5d ago

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This iss…

TwilightISC · BIND 9EPSS 0.49%via NVD
CVE-2026-76151Medium· 4.6
5d ago

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Sunlitqt · qtEPSS 0.64%via NVD
CVE-2026-87529Critical· 9.6⚖ disputed
1w ago

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-78512High· 8.8
1w ago

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-69822High· 7.8
1w ago

Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1809EPSS 0.31%via NVD
CVE-2026-69578High· 7.0
1w ago

Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.

Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-69535High· 7.8
1w ago

Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.25%via NVD
CVE-2026-69512High· 8.0
1w ago

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.77%via NVD
CVE-2026-68895Medium· 5.5
1w ago

Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.

Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.28%via NVD
CVE-2026-68880High· 8.0
1w ago

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.43%via NVD
CVE-2026-86315Medium· 6.2
2w ago

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

SunlitSamsung Opensource · EscargotEPSS 0.12%via NVD
CVE-2026-80213Medium· 4.0
3w ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but t…

SunlitRuby · resolvEPSS 0.35%via NVD
CVE-2026-49263None
1mo ago

Capstone is a disassembly framework

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-…

SunlitEPSS 0.19%via NVD
CVE-2026-62739High· 7.8
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1809EPSS 0.25%via CVEORG
CVE-2026-62769Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-63525High· 7.8
1mo ago

Microsoft Office Word Remote Code Execution Vulnerability

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.38%via CVEORG
CVE-2026-62883Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62881Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-65798Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-65797Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-68804High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.35%via CVEORG
CVE-2026-65795Medium· 6.7
1mo ago

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-62698High· 7.8
1mo ago

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.36%via NVD
CVE-2026-49792High· 7.8
2mo ago

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50332High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50357High· 7.8
2mo ago

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-55142Medium· 5.5
2mo ago

Microsoft Word Information Disclosure Vulnerability

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.60%via CVEORG
CVE-2026-56650High· 7.8
2mo ago

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2025-6965High· 7.7PoC
1y ago

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Midnightsqlite · sqliteEPSS 73%via NVD
CWE-197 vulnerabilities (CVEs) · VulnSea