VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-63923High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c qu…

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c qu…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.17%via NVD
CVE-2026-16225Medium· 6.3
2mo ago

A security flaw has been discovered in davenardella snap7 up to 1.4.3

A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bou…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-16095High· 8.8
2mo ago

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. Th…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-59197High· 8.2
2mo ago

Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)

A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.58%via CSAF
CVE-2026-15545High· 8.8
2mo ago

A vulnerability was identified in Shibby Tomato up to 1.28.0000

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The att…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-10666High· 8.1
2mo ago

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - en…

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - en…

▾ TwilightEPSS 0.65%via NVD
CVE-2026-10665High· 7.4
2mo ago

In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound transport-data payload into a fixed pool buffer of CONFIG_WIREGUARD_BUF_LEN bytes before decryption

In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound transport-data payload into a fixed pool buffer of CONFIG_WIREGUARD_BUF_LEN bytes before decryption. The call net_…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-10664Medium· 5.0
2mo ago

The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (Target Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info event into the fi…

The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (Target Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info event into the fi…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-10660Medium· 6.4
2mo ago

The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes…

The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-55233High· 7.5
2mo ago

OpenResty is a high performance web platform

OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 h…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-41154None
2mo ago

Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer…

Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-55827High· 7.5
2mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while al…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-55687High· 7.5
2mo ago

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg_parse_marker.c …

▾ TwilightEPSS 0.70%via NVD
CVE-2026-21042High· 8.7
2mo ago

Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.

Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.

▾ TwilightSamsung Mobile · Samsung Mobile DevicesEPSS 0.44%via NVD
CVE-2026-59691High· 7.1
2mo ago

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path wri…

▾ TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.60%via NVD
CVE-2026-33799Medium· 4.3
2mo ago

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, c…

▾ Sunlitjuniper · junosEPSS 0.37%via NVD
CVE-2026-15105Medium· 6.3
2mo ago

A flaw has been found in davenardella snap7 up to 1.4.3

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. …

▾ SunlitEPSS 0.38%via NVD
CVE-2022-46292High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)

Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2026-14612Medium· 4.2
2mo ago

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-58592High· 8.3PoC
2mo ago

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp pa…

▾ MidnightLadybirdBrowser · LadybirdEPSS 0.55%via NVD
CVE-2026-14400High· 8.3
2mo ago

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-14397Critical· 9.6
2mo ago

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-14395High· 8.8
2mo ago

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-14392Critical· 9.6
2mo ago

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2022-37331High· 7.8
2mo ago

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

▾ Twilightopenbabel · openbabelEPSS 0.68%via GHSA
CVE-2022-41793High· 7.8
2mo ago

Open Babel has out-of-bounds write in CSR PadString (title field)

Open Babel has out-of-bounds write in CSR PadString (title field)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-43467High· 7.8
2mo ago

Open Babel has out-of-bounds write in PQS coord_file parser

Open Babel has out-of-bounds write in PQS coord_file parser

▾ Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2022-43607High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOL2 attribute/value parser

Open Babel has out-of-bounds write in MOL2 attribute/value parser

▾ Twilightopenbabel · openbabelEPSS 0.78%via GHSA
CVE-2022-46289High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser

Open Babel has out-of-bounds write in ORCA nAtoms parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46290High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CWE-787 vulnerabilities (CVEs) — page 15 · VulnSea