VulnSea

CWE-823

CVEs classified under CWE-823, newest first.

11 CVEsRSS

CVE-2026-48977High· 7.7
5d ago

OpenSlide is a C library for reading whole slide image files

OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF fi…

Twilightopenslide · openslideEPSS 0.30%via NVD
CVE-2026-89678High· 7.0
1w ago

kernel: nfsd: fix partial-write detection in nfsd_direct_write (CVE-2026-89678)

A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The `nfsd_direct_write()` function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic f…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.35%via CSAF
CVE-2026-31912Medium· 5.5
2w ago

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular …

SunlitThe Tcpdump Group · libpcapEPSS 0.10%via NVD
CVE-2026-59982High· 7.1
4w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds po…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.31%via NVD
CVE-2026-75595Critical· 7.4
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

Midnightnetty · io.netty:netty-handlerEPSS 0.32%via NVD
CVE-2026-64255High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without check…

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without check…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.22%via NVD
CVE-2026-12290High· 8.1
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-46244Critical· 9.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport heade…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport heade…

Midnightlinux · linux_kernelEPSS 0.32%via NVD
CVE-2026-32829High· 7.5
6mo ago

lz4_flex is a pure Rust implementation of LZ4 compression/decompression

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression op…

Twilightpseitz · lz4_flexEPSS 0.61%via NVD
CVE-2024-42391Medium· 4.3
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Sunlitcesanta · mongooseEPSS 0.28%via NVD
CVE-2024-42386High· 8.2
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Twilightcesanta · mongooseEPSS 0.38%via NVD
CWE-823 vulnerabilities (CVEs) · VulnSea