VulnSea

CWE-805

CVEs classified under CWE-805, newest first.

21 CVEsRSS

CVE-2026-20290Medium· 5.8
5d ago

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. Th…

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. Th…

SunlitCisco · Cisco Secure Firewall Threat Defense (FTD) SoftwareEPSS 0.19%via NVD
CVE-2026-77412High· 8.9
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer.…

Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-90804Medium· 4.8PoC
1w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument…

Twilightgnu · binutilsEPSS 0.14%via NVD
CVE-2026-90803Medium· 5.3PoC
1w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads …

Twilightgnu · binutilsEPSS 0.14%via NVD
CVE-2026-80965Medium· 5.5
1w ago

kernel: ALSA: serial-u16550: Check card index validity at probe (CVE-2026-80965)

A flaw was found in the Linux kernel's ALSA serial-u16550 driver. This vulnerability occurs because the driver does not properly validate the card index when a device is manually bound via the sysfs interface. A local user could exploit th…

SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89674Medium· 5.5⚖ disputed
1w ago

kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (CVE-2026-89674)

A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…

SunlitRed Hat · LinuxEPSS 0.52%via CSAF
CVE-2026-89628Medium· 5.5
1w ago

kernel: HID: picolcd: clamp eeprom debugfs read to bytes actually received (CVE-2026-89628)

A flaw was found in the Human Interface Device (HID) picolcd driver in the Linux kernel. A local attacker with root privileges, by using a specially crafted or spoofed picoLCD device, could exploit an out-of-bounds read vulnerability in th…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89728Medium· 5.5
1w ago

kernel: i3c: renesas: Fix out-of-bounds access for newdevs mask (CVE-2026-89728)

A flaw was found in the Linux kernel's I3C Renesas driver. When the I3C bus is empty and software initiates Dynamic Address Assignment (DAA), an out-of-bounds access can occur. This is due to an incorrect calculation of the newly discovere…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.16%via CSAF
CVE-2026-89719Medium· 4.1
1w ago

In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state() read_block_state() calculates nr_pages before taking dev_lock

In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state() read_block_state() calculates nr_pages before taking dev_lock. If the device is reset and reinitialized with a sm…

SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-86142Medium· 6.9
2w ago

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

Sunlitxmlsoft · libxml2EPSS 0.15%via NVD
CVE-2026-14670High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, …

Twilightpostgresql · postgresqlEPSS 0.44%via NVD
CVE-2026-15028Low· 3.9
2mo ago

A flaw was found in libarchive

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.…

SunlitRed Hat · libarchive-mainEPSS 0.20%via NVD
CVE-2026-53016High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into…

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into…

Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-44893High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls…

Twilightnetty · nettyEPSS 0.62%via NVD
CVE-2026-8091Critical· 9.8
4mo ago

Incorrect boundary conditions in the Audio/Video: Playback component

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Midnightmozilla · firefoxEPSS 0.47%via NVD
CVE-2026-31607Critical· 9.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

Midnightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2026-41035High· 7.4
5mo ago

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configuratio…

Twilightsamba · rsyncEPSS 0.39%via NVD
CVE-2026-6245Medium· 5.5
5mo ago

A flaw was found in the System Security Services Daemon (SSSD)

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-ter…

Sunlitfedoraproject · sssdEPSS 0.14%via NVD
CVE-2026-4224High· 7.5
6mo ago

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

Twilightpython · pythonEPSS 0.69%via NVD
CVE-2026-1837High· 7.5
7mo ago

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting colo…

Twilightlibjxl_project · libjxlEPSS 0.29%via NVD
CVE-2026-0716Medium· 4.8PoC
8mo ago

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. T…

TwilightRed Hat · libsoup3EPSS 0.36%via NVD
CWE-805 vulnerabilities (CVEs) · VulnSea