Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Unclassified HIGH 7.3
CVE-2025-70103

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

Patch available
Fix from $1,950 2026-05-27
Aspera High Speed Transfer Endpoint CRITICAL 9.8
CVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $2,300 2026-05-27
Unclassified HIGH 7.3
CVE-2026-38427

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Lengt…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-9605

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utili…

Patch available
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-44983

smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of s…

Mitigation only
Fix from $1,950 2026-05-26
Fastnetmon CRITICAL 9.8
CVE-2026-48689

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary…

Fix: after 1.2.9
Fix from $2,300 2026-05-26
HTTP Server HIGH 8.0
CVE-2026-8834

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
Fastnetmon HIGH 7.1
CVE-2026-48690

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.…

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Fastnetmon CRITICAL 9.8
CVE-2026-48691

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4Unicas…

Fix: after 1.2.9
Fix from $2,300 2026-05-26
Freerdp HIGH 8.8
CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap me…

Fix: 3.26.0+
Fix from $1,950 2026-05-26
Squirrel MEDIUM 5.3
CVE-2026-9541

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnu…

Fix: after 3.2
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.3
CVE-2026-48135

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

No fix yet
Fix from $1,600 2026-05-26
Unclassified HIGH 8.1
CVE-2026-48131

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This …

Mitigation only
Fix from $1,950 2026-05-26
Mediainfolib HIGH 7.8
CVE-2026-25713

MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability

No fix yet
Fix from $1,950 2026-05-26
Unclassified MEDIUM 5.3
CVE-2026-9500

A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of t…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 5.3
CVE-2026-9502

A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the compone…

Patch available
Fix from $1,600 2026-05-25
Unclassified MEDIUM 5.6
CVE-2026-9365

A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the c…

Patch available
Fix from $1,600 2026-05-24
Nginx Open Source HIGH 8.1
CVE-2026-9256EPSS 10%

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses …

Fix: 1.30.2 / 2.6.2+
Fix from $1,950 2026-05-22
FreeBSD MEDIUM 5.5
CVE-2026-45252

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list o…

Mitigation only
Fix from $1,600 2026-05-21
Unclassified CRITICAL 9.9
CVE-2026-44050

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute…

Mitigation only
Fix from $2,300 2026-05-21
Hardened Images MEDIUM 6.5
CVE-2026-9149

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat…

Fix: after 0.7.36
Fix from $1,600 2026-05-21
Linux Imaging And Printing CRITICAL 9.8
CVE-2026-8631

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati…

Fix: 3.26.4+
Fix from $2,300 2026-05-20
Chrome HIGH 7.5
CVE-2026-9123

Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary…

Fix: 148.0.7778.179+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9119

Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 148.0.7778.178+
Fix from $1,950 2026-05-20
Mediainfolib HIGH 7.8
CVE-2026-22554

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

Mitigation only
Fix from $1,950 2026-05-20
Malware Protection Engine HIGH 8.1
CVE-2026-45584

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Unclassified HIGH 7.1
CVE-2026-32741

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_i…

Mitigation only
Fix from $1,950 2026-05-19
Kitty HIGH 8.8
CVE-2026-33633

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process w…

Fix: 0.47.0+
Fix from $1,950 2026-05-19
Njs CRITICAL 9.8
CVE-2026-8711

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,…

Fix: 0.9.9+
Fix from $2,300 2026-05-19
Escargot CRITICAL 9.8
CVE-2026-47311

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da85…

Patch available
Fix from $2,300 2026-05-19