Vulnerability index

Browse CVEs

2,635 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Libxfont HIGH 8.8
CVE-2026-56002

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec…

Fix: 2.0.8+
Fix from $1,950 2026-07-08
Libxfont HIGH 8.8
CVE-2026-56003

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf…

Fix: 2.0.8+
Fix from $1,950 2026-07-08
Libxfont HIGH 8.8
CVE-2026-56001

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the…

Fix: 2.0.8+
Fix from $1,950 2026-07-08
X Server HIGH 7.8
CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a …

Fix: 21.2.24 / 24.1.13+
Fix from $1,950 2026-07-08
Wget HIGH 7.1
CVE-2026-58471

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that…

Fix: after 1.25.0
Fix from $1,950 2026-07-07
Directory Server MEDIUM 5.3
CVE-2026-14940

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 8.8
CVE-2026-11610

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protec…

Mitigation only
Fix from $1,950 2026-07-07
Radare2 HIGH 7.8
CVE-2026-14759

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the …

Fix: 6.1.8+
Fix from $1,950 2026-07-05
Edge Chromium HIGH 8.8
CVE-2026-56645

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-14610

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/…

Patch available
Fix from $1,600 2026-07-03
PHP MEDIUM 5.3
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenS…

Fix: 8.2.32 / 8.3.32+
Fix from $1,600 2026-07-03
Unclassified HIGH 7.3
CVE-2026-58379

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitra…

Mitigation only
Fix from $1,950 2026-07-03
Chrome HIGH 8.3
CVE-2026-14427

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-14415

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI ge…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-14385

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a c…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.3
CVE-2025-15666

A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::Sc…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.7
CVE-2026-20462

In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious ac…

Mitigation only
Fix from $1,600 2026-07-01
Chrome MEDIUM 5.8
CVE-2026-13976

Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome HIGH 8.8
CVE-2026-13884

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traff…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome HIGH 8.8
CVE-2026-13835

Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13798

Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Unclassified HIGH 7.5
CVE-2026-51218

A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.5
CVE-2026-51219

A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.6
CVE-2026-13590

A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/head…

Patch available
Fix from $1,600 2026-06-29
Unclassified HIGH 7.3
CVE-2026-12912

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.6
CVE-2026-13588

A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.6
CVE-2026-13589

A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/Teln…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-30040

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the c…

Mitigation only
Fix from $1,600 2026-06-26
Rtklib MEDIUM 6.5
CVE-2026-56789

RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory…

Fix: after 2.4.3
Fix from $1,600 2026-06-25
Socat CRITICAL 9.8
CVE-2026-56123

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite ad…

Fix: 1.8.1.2+
Fix from $2,300 2026-06-25