VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-59181Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value g…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-10027High· 8.1
1w ago

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

▾ Twilightibm · mqEPSS 0.38%via NVD
CVE-2026-81627High· 8.2PoC
1w ago

A flaw was found in QEMU

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…

▾ MidnightRed Hat · qemu-kvmEPSS 0.19%via NVD
CVE-2026-15579High· 8.8
1w ago

An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing

An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly l…

▾ TwilightMoxa · TN-4500B SeriesEPSS 0.44%via NVD
CVE-2026-93451Medium· 6.5
1w ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Atta…

▾ Sunlitxerial · snappy-javaEPSS 0.50%via NVD
CVE-2026-93452High· 7.5PoC
1w ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination bu…

▾ Midnightxerial · snappy-javaEPSS 0.68%via NVD
CVE-2026-54634High· 7.3
1w ago

Hamlib is a ham radio control library for radios, rotators, and amplifiers

Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a NUL byte at buf[b…

▾ TwilightHamlib · HamlibEPSS 0.44%via NVD
CVE-2026-73639Critical· 9.1
1w ago

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creat…

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creat…

▾ MidnightEPSS 0.70%via NVD
CVE-2026-93393High· 8.1
1w ago

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outsid…

▾ TwilightMongoDB Inc. · C DriverEPSS 0.47%via NVD
CVE-2026-54692High· 7.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using t…

▾ MidnightHappySeaFox · sailEPSS 0.19%via NVD
CVE-2026-54627Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in …

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-54626Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-by…

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-93015Medium· 6.3
1w ago

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds…

▾ SunlitBlueKitchen GmbH · BTstackEPSS 0.39%via NVD
CVE-2026-92880Medium· 6.3
1w ago

A weakness has been identified in vgmstream up to r2117

A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-24073High· 7.8
1w ago

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-24074High· 7.8
1w ago

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

▾ Twilightqualcomm · iqx5121_firmwareEPSS 0.07%via NVD
CVE-2026-25280High· 7.8
1w ago

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.07%via NVD
CVE-2026-92786High· 7.8
1w ago

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node referenc…

▾ Twilightlightgbm-org · LightGBMEPSS 0.19%via NVD
CVE-2026-91097Critical· 9.8PoC⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Abyssalhp · linux_imaging_and_printingEPSS 1.0%via NVD
CVE-2026-86107Medium· 5.9
1w ago

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful …

▾ SunlitArista Networks · VeloCloudEPSS 0.37%via NVD
CVE-2026-82717Critical· 9.8
1w ago

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts whe…

▾ Midnightnlnetlabs · unboundEPSS 0.78%via NVD
CVE-2026-91711High· 8.8
1w ago

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-58773Medium· 6.7
1w ago

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58734High· 7.0
1w ago

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-19773Critical· 9.80day
1w ago

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is no…

▾ Hadallibwebsockets · libwebsocketsEPSS 0.65%via NVD
CVE-2026-19885High· 7.80day
1w ago

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interactio…

▾ AbyssalOriginLab · Origin ViewerEPSS 0.17%via NVD
CVE-2026-92179High· 7.80day
1w ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVE-2026-92177High· 7.80day
1w ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVE-2026-0171High· 8.8
1w ago

In multiple locations, there is a possible out-of-bounds write due to a logic error in the code

In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.29%via NVD
CVE-2026-0170High· 8.8
1w ago

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not n…

▾ Twilightgoogle · androidEPSS 0.28%via NVD
CWE-787 vulnerabilities (CVEs) — page 3 · VulnSea