CWE-681
CVEs classified under CWE-681, newest first.
13 CVEsRSS
CVE-2026-77412High· 8.9RabbitMQ amqp091-go is a Go AMQP 0.9.1 client
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer.…
CVE-2026-89450High· 7.0kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field (CVE-2026-89450)
A flaw was found in the Linux kernel's iommu/tegra241-cmdqv module. A Virtual Machine Manager (VMM) can exploit this vulnerability by providing a virtual Stream ID (vSID) that exceeds the intended 20-bit width of the SID_MATCH field. This …
CVE-2026-69438High· 8.1Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.
CVE-2026-84970Medium· 6.2A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that tex…
CVE-2026-82457High· 7.8su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that trun…
CVE-2026-61799Medium· 5.3netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
CVE-2026-6426Medium· 4.4A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted…
CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
CVE-2026-55768NoneGoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 3…
CVE-2026-50402High· 7.8PoCNTFS Elevation of Privilege Vulnerability
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-55123High· 7.8Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-53923High· 7.5vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-4602High· 7.5PoCVersions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and brea…