VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-65395Medium· 6.5
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing…

▾ Sunlitapple · ipadosEPSS 0.46%via NVD
CVE-2026-84519Medium· 6.5
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a disk image with malic…

▾ Sunlitapple · ipadosEPSS 0.42%via NVD
CVE-2026-64736High· 7.1
1w ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpec…

▾ Twilightapple · ipadosEPSS 0.16%via NVD
CVE-2026-84523Medium· 5.5
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27…

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-86882Medium· 6.5
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27…

▾ Sunlitapple · ipadosEPSS 0.47%via NVD
CVE-2026-84515High· 7.8
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.

▾ Twilightapple · macosEPSS 0.17%via NVD
CVE-2026-84611High· 7.3
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27…

▾ Twilightapple · ipadosEPSS 0.17%via NVD
CVE-2026-43761Medium· 6.5
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.

▾ Sunlitapple · macosEPSS 0.40%via NVD
CVE-2026-84575High· 7.8
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously…

▾ Twilightapple · ipadosEPSS 0.17%via NVD
CVE-2026-86876Medium· 5.2
1w ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandb…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-19280Medium· 5.2
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

▾ SunlitIBM · iEPSS 0.12%via NVD
CVE-2026-19542Medium· 5.6
1w ago

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

▾ SunlitThe GNU C Library · glibcEPSS 0.23%via NVD
CVE-2026-19499High· 7.7
1w ago

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

▾ TwilightThe GNU C Library · glibcEPSS 0.30%via NVD
CVE-2026-90947High· 7.8
1w ago

A flaw was found in GIMP

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attack…

▾ TwilightRed Hat · gimpEPSS 0.19%via NVD
CVE-2026-33967Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corrupt…

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.12%via NVD
CVE-2026-33960Low· 2.8
1w ago

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation,…

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.12%via NVD
CVE-2026-33957Medium· 4.2
1w ago

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information…

▾ SunlitSamsung · Exynos 1580 firmwareEPSS 0.13%via NVD
CVE-2026-33956Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.12%via NVD
CVE-2026-23791Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mo…

▾ SunlitSamsung · Exynos 1280 firmwareEPSS 0.09%via NVD
CVE-2026-82782Medium· 4.3
1w ago

Out-of-bounds write vulnerability exists in CONPROSYS nano Series

Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.46%via NVD
CVE-2026-23793Low· 3.5
1w ago

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.20%via NVD
CVE-2026-90949High· 7.8
1w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-90948High· 7.8
1w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-54334Critical· 9.8
1w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT …

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
CVE-2026-54333Critical· 9.8
1w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read…

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
CVE-2026-89266High· 8.2PoC
2w ago

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimension…

▾ Midnightnothings · stb_vorbisEPSS 0.64%via NVD
CVE-2026-90559High· 7.5
2w ago

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compress…

▾ Twilightxerial · snappy-javaEPSS 0.63%via NVD
CVE-2026-80986High· 7.0⚖ disputed
2w ago

kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)

A flaw was found in the Linux kernel's SMC-Rv2 network component. A remote attacker could exploit this vulnerability by sending a specially crafted message during an SMC-Rv2 link addition. This can lead to a slab-out-of-bounds write, poten…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-80945Critical· 9.1⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst w…

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst w…

▾ MidnightLinux · LinuxEPSS 0.52%via NVD
CVE-2026-80943Medium· 5.5⚖ disputed
2w ago

kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (CVE-2026-80943)

A flaw was found in the Linux kernel's rtlwifi driver. This vulnerability occurs when the `rtl92du_tx_fill_desc()` function uses a Quality of Service (QoS) Traffic Identifier (TID) value greater than 8 as an index into an array that only h…

▾ SunlitRed Hat · LinuxEPSS 0.37%via CSAF
CWE-787 vulnerabilities (CVEs) — page 6 · VulnSea