VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2025-7519Medium· 6.7
1y ago

A flaw was found in polkit

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not…

▾ Sunlitredhat · openshift_container_platformEPSS 0.19%via NVD
CVE-2025-6021High· 7.5PoC
1y ago

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…

▾ Midnightxmlsoft · libxml2EPSS 1.4%via NVD
CVE-2025-5917Low· 2.8
1y ago

A vulnerability has been identified in the libarchive library

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an…

▾ Sunlitlibarchive · libarchiveEPSS 0.20%via NVD
CVE-2025-1252High· 7.1
1y ago

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.…

▾ Twilightrti · connext_professionalEPSS 0.15%via NVD
CVE-2025-1254High· 7.4
1y ago

Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers

Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7,…

▾ Twilightrti · connext_professionalEPSS 0.24%via NVD
CVE-2025-22056High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every genev…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every genev…

▾ Twilightlinux · linux_kernelEPSS 0.32%via NVD
CVE-2025-22457Critical· 9.0CISA KEV0dayPoC
1y ago

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2025-21927Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, …

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, …

▾ Midnightlinux · linux_kernelEPSS 0.49%via NVD
CVE-2025-21914High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: slimbus: messaging: Free transaction ID in delayed interrupt scenario In case of interrupt delay for any reason, slim_do_transfer() returns timeout error but the trans…

In the Linux kernel, the following vulnerability has been resolved: slimbus: messaging: Free transaction ID in delayed interrupt scenario In case of interrupt delay for any reason, slim_do_transfer() returns timeout error but the trans…

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2025-21919High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can orig…

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can orig…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2025-21868High· 7.5⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_a…

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_a…

▾ Twilightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2025-22225High· 8.2CISA KEV0day
1y ago

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

▾ Abyssalvmware · cloud_foundationEPSS 1.00%via NVD
CVE-2024-45782High· 7.8
1y ago

A flaw was found in the HFS filesystem

A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the volume name's length…

▾ Twilightgnu · grub2EPSS 0.22%via NVD
CVE-2025-1125High· 7.8
1y ago

When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows

When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows. A malic…

▾ Twilightgnu · grub2EPSS 0.43%via NVD
CVE-2024-45780Medium· 6.7
1y ago

A flaw was found in grub2

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length…

▾ Sunlitgnu · grub2EPSS 0.29%via NVD
CVE-2025-0686Medium· 6.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperl…

▾ Sunlitgnu · grub2EPSS 0.28%via NVD
CVE-2025-0685Medium· 6.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for intege…

▾ Sunlitgnu · grub2EPSS 0.28%via NVD
CVE-2025-0684Medium· 6.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly …

▾ Sunlitgnu · grub2EPSS 0.28%via NVD
CVE-2024-10918Medium· 4.8
1y ago

Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length.

Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length.

▾ Sunlitlibmodbus · libmodbusEPSS 0.56%via NVD
CVE-2025-21785High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does …

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does …

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2025-21772High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: partitions: mac: fix handling of bogus partition table Fix several issues in partition probing: - The bailout for a bad partoffset must use put_dev_sector(), since t…

In the Linux kernel, the following vulnerability has been resolved: partitions: mac: fix handling of bogus partition table Fix several issues in partition probing: - The bailout for a bad partoffset must use put_dev_sector(), since t…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2025-21735High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corr…

▾ Twilightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2025-21734High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix copy buffer page size For non-registered buffer, fastrpc driver copies the buffer and pass it to the remote subsystem

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix copy buffer page size For non-registered buffer, fastrpc driver copies the buffer and pass it to the remote subsystem. There is a problem with curre…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2022-49051Medium· 6.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) …

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) …

▾ Sunlitlinux · linux_kernelEPSS 0.44%via NVD
CVE-2022-49044High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: dm integrity: fix memory corruption when tag_size is less than digest size It is possible to set up dm-integrity in such a way that the "tag_size" parameter is less th…

In the Linux kernel, the following vulnerability has been resolved: dm integrity: fix memory corruption when tag_size is less than digest size It is possible to set up dm-integrity in such a way that the "tag_size" parameter is less th…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2025-26598High· 7.8
1y ago

An out-of-bounds write flaw was found in X.Org and Xwayland

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the c…

▾ Twilighttigervnc · tigervncEPSS 0.40%via NVD
CVE-2025-26596High· 7.8
1y ago

A heap overflow flaw was found in X.Org and Xwayland

A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.

▾ Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2025-26595High· 7.8
1y ago

A buffer overflow flaw was found in X.Org and Xwayland

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buf…

▾ Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2025-0690Medium· 6.1PoC
1y ago

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, wit…

▾ TwilightEPSS 0.72%via NVD
CVE-2025-0677Medium· 6.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. …

▾ SunlitEPSS 0.33%via NVD
CWE-787 vulnerabilities (CVEs) — page 22 · VulnSea