VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-53792Medium· 6.5
1mo ago

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block…

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-14676High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor ve…

▾ Twilightpostgresql · postgresqlEPSS 0.44%via NVD
CVE-2026-14662High· 8.8PoC
1mo ago

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary …

▾ Midnightpostgresql · postgresqlEPSS 0.46%via NVD
CVE-2026-18888Medium· 6.5
1mo ago

The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer

The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the dr…

▾ Sunlitmongodb · bi_connector_odbc_driverEPSS 0.32%via NVD
CVE-2026-16907High· 7.6
1mo ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

▾ Twilightibm · iEPSS 0.57%via NVD
CVE-2026-29035Medium· 6.5
1mo ago

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB …

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB …

▾ SunlitEPSS 0.61%via NVD
CVE-2026-50059High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing special…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-50064High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing special…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-73066High· 7.1
1mo ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolv…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.13%via NVD
CVE-2026-62817High· 8.8
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

▾ TwilightMicrosoft · Windows Server 2019EPSS 0.53%via CVEORG
CVE-2026-68806High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-18693High· 7.6
1mo ago

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert i…

▾ Twilightmongodb · mongodbEPSS 0.34%via NVD
CVE-2026-11736Medium· 4.9
1mo ago

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

▾ Sunlitnetgear · rax20_firmwareEPSS 0.51%via NVD
CVE-2026-70354High· 7.8
1mo ago

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.36%via CVEORG
CVE-2026-62871High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 0.47%via CVEORG
CVE-2026-71969Medium· 6.7
1mo ago

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted A…

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted A…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-68159Critical· 9.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.74%via NVD
CVE-2026-19387High· 7.6
1mo ago

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV …

▾ TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.38%via NVD
CVE-2026-15534Medium· 5.7
1mo ago

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

▾ SunlitRed Hat · perlEPSS 0.26%via NVD
CVE-2026-17264Medium· 4.3
1mo ago

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-43629High· 8.1
1mo ago

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access…

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access…

▾ Twilightggml · llama.cppEPSS 0.70%via NVD
CVE-2026-8325High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary…

▾ Twilightautodesk · revitEPSS 0.19%via NVD
CVE-2026-5857High· 8.1
1mo ago

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP s…

▾ TwilightEPSS 0.92%via NVD
CVE-2026-19173High· 8.3
1mo ago

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-19148High· 8.3
1mo ago

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-24253High· 8.2
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

▾ Twilightnvidia · dynamoEPSS 0.64%via NVD
CVE-2026-10849High· 8.2
1mo ago

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c)

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the receive…

▾ Twilightzephyrproject · zephyrEPSS 0.51%via NVD
CVE-2026-20485None
1mo ago

In HFRP, there is a possible out of bounds write due to a missing bounds check

In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-20481None
1mo ago

In geniezone, there is a possible out of bounds write due to a missing bounds check

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for expl…

▾ SunlitEPSS 0.17%via NVD
CWE-787 vulnerabilities (CVEs) — page 13 · VulnSea