VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2022-46291High· 7.8
2mo ago

Open Babel has out-of-bounds write in Gaussian translationVectors[]

Open Babel has out-of-bounds write in Gaussian translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46293High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46294High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46295High· 7.8
2mo ago

Open Babel has out-of-bounds write in MSI translationVectors[]

Open Babel has out-of-bounds write in MSI translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2025-10995Low· 7.8
2mo ago

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2026-10643High· 8.7
3mo ago

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before wri…

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before wri…

▾ Twilightzephyrproject · zephyrEPSS 0.16%via NVD
CVE-2026-58049High· 8.6
3mo ago

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a P…

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a P…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 3.0 for RHEL 9EPSS 0.50%via NVD
CVE-2026-53465Medium· 6.2
3mo ago

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.16%via GHSA
CVE-2026-53266High· 8.8CISA KEVPoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…

▾ Abyssallinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-53196Medium· 6.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated w…

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated w…

▾ Sunlitlinux · linux_kernelEPSS 0.27%via NVD
CVE-2026-53209High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum extended advertising payload

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum extended advertising payload. When hci…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53205High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read and write indices in the firmware log buffer are within valid bounds (< data_size) befo…

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read and write indices in the firmware log buffer are within valid bounds (< data_size) befo…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53203High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_info_ioctl Add validation that the info size returned from the metric stream info query is not exceeded when checked ag…

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_info_ioctl Add validation that the info size returned from the metric stream info query is not exceeded when checked ag…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-48724Medium· 5.5
3mo ago

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-53461High· 7.5
3mo ago

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

▾ TwilightMagick · Magick.NET-Q16-AnyCPUEPSS 0.63%via GHSA
CVE-2026-53059High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_secto…

In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_secto…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-53016High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into…

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-53002Critical· 9.8⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflo…

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflo…

▾ Midnightlinux · linux_kernelEPSS 0.53%via NVD
CVE-2026-56340High· 8.8
3mo ago

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…

▾ Twilightvllm · vllmEPSS 0.64%via NVD
GHSA-78fp-cf4h-g36pHigh· 8.8
3mo ago

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

▾ Twilightvllm · vllmvia GHSA
CVE-2026-56211High· 7.1
3mo ago

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted vide…

▾ TwilightRed Hat · aomEPSS 0.88%via NVD
CVE-2026-56209High· 7.1
3mo ago

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer i…

▾ TwilightRed Hat · aomEPSS 0.64%via NVD
CVE-2026-54592High· 7.5
3mo ago

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

▾ Twilightoj · ojEPSS 0.46%via GHSA
CVE-2026-2674High· 8.1⚖ disputed
3mo ago

Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers

Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, fro…

▾ Twilightrti · connext_professionalEPSS 0.31%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

▾ Midnightf5 · dosEPSS 2.4%via NVD
CVE-2026-12298Medium· 5.4
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-12292High· 8.1
3mo ago

Incorrect boundary conditions in the Web Audio component

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Twilightmozilla · firefoxEPSS 0.49%via NVD
CVE-2026-46331High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_…

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_…

▾ MidnightLinux · LinuxEPSS 0.20%via NVD
CVE-2026-8357High· 7.8
3mo ago

LibreOffice Calc compiles cell formulas when opening a spreadsheet

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-54410High· 8.6
3mo ago

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

▾ TwilightEPSS 0.86%via NVD
CWE-787 vulnerabilities (CVEs) — page 16 · VulnSea