VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-20478None
1mo ago

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS1098145…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-20477None
1mo ago

In display, there is a possible out of bounds write due to a missing bounds check

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploi…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-20476None
1mo ago

In ccci, there is a possible out of bounds read due to a missing bounds check

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Iss…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-20475None
1mo ago

In display, there is a possible out of bounds write due to a missing bounds check

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploi…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-20472None
1mo ago

In TFA, there is a possible out of bounds write due to a missing bounds check

In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Pa…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-20471None
1mo ago

In DA, there is a possible out of bounds write due to a missing bounds check

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-20468None
1mo ago

In apusys, there is a possible escalation of privilege due to a confused deputy

In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploita…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-20466None
1mo ago

In sec boot, there is a possible escalation of privilege due to a heap buffer overflow

In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. U…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-20464None
1mo ago

In hevc decoder, there is a possible out of bounds write due to an integer overflow

In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exp…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-10848High· 7.0
1mo ago

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(…

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-68579Critical· 9.6
1mo ago

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c)

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with …

▾ MidnightEPSS 0.47%via NVD
CVE-2026-34641High· 7.8
1mo ago

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a maliciou…

▾ Twilightadobe · premiereEPSS 0.26%via NVD
CVE-2026-54715None
1mo ago

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing ver…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-17675Critical· 9.6
1mo ago

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-43748Critical· 9.8
2mo ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

▾ Midnightapple · macosEPSS 0.58%via NVD
CVE-2026-59250High· 8.3
2mo ago

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a sing…

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a sing…

▾ TwilightErlang · otpEPSS 1.2%via NVD
CVE-2026-64381High· 7.8⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDU…

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDU…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64402High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls smb_sync_perf_buffer() to copy…

In the Linux kernel, the following vulnerability has been resolved: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls smb_sync_perf_buffer() to copy…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-64270High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms11…

In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms11…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64304High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but…

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-64268Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at…

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.71%via NVD
CVE-2026-64217High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get i…

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get i…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-62363Medium· 5.0
2mo ago

ImageMagick: Heap Buffer Over-Write in fx operation

ImageMagick: Heap Buffer Over-Write in fx operation

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.13%via GHSA
CVE-2026-55597Medium· 5.5
2mo ago

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-54696Low· 3.7
2mo ago

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

▾ Sunlitjson · jsonEPSS 0.38%via GHSA
CVE-2026-47058High· 7.4
2mo ago

Vulnerability in Oracle Java SE (component: Scripting)

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via …

▾ TwilightRed Hat · Red Hat OpenJDK 11 ELS for RHEL 8EPSS 0.39%via NVD
CVE-2026-47010Low· 3.7
2mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19,…

▾ Sunlitoracle · graalvmEPSS 0.25%via NVD
CVE-2026-64191High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] as the transfer length

In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] as the transfer length. The existing che…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.13%via NVD
CVE-2026-59948High· 7.0
2mo ago

Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer: Arbitrary file write outside vendor via malicious transitive package name

▾ Twilightcomposer · composer/composerEPSS 0.16%via GHSA
CVE-2026-64074High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to i…

In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to i…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CWE-787 vulnerabilities (CVEs) — page 14 · VulnSea