Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Unclassified MEDIUM 5.1
CVE-2026-44662

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::c…

Mitigation only
Fix from $1,600 2026-05-14
Chrome HIGH 8.3
CVE-2026-8525

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8529

Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8531

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption vi…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8509

Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Libsixel HIGH 7.8
CVE-2026-44636

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's…

Fix: 1.8.7-r2+
Fix from $1,950 2026-05-14
Openimageio HIGH 7.8
CVE-2026-43906

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Pan Os CRITICAL 9.8
CVE-2026-0264

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker wi…

Fix: 10.2.7 / 10.2.10+
Fix from $2,300 2026-05-13
Dos HIGH 8.1
CVE-2026-42945EPSS 66%

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is …

Fix: after 5.12.1
Fix from $1,950 2026-05-13
Unclassified HIGH 8.8
CVE-2025-62624

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting…

Mitigation only
Fix from $1,950 2026-05-13
Arubaos HIGH 7.5
CVE-2026-23827

A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote atta…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Windows 11 24h2 HIGH 7.8
CVE-2026-42896

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8457 / 10.0.26100.32860+
Fix from $1,950 2026-05-12
365 Copilot HIGH 7.8
CVE-2026-42831

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19822.20190+
Fix from $1,950 2026-05-12
Windows 11 23h2 CRITICAL 9.8
CVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Fix: 10.0.22631.7079 / 10.0.25398.2330+
Fix from $2,300 2026-05-12
Windows 10 1607 HIGH 8.8
CVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40407

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40398

Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40377

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 MEDIUM 6.2
CVE-2026-40380

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40362

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20128+
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40363

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19822.20190+
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows Server 2012 HIGH 7.8
CVE-2026-35420

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-35421

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Illustrator HIGH 7.8
CVE-2026-34687

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code executio…

Fix: 29.8.7 / 30.4+
Fix from $1,950 2026-05-12
After Effects HIGH 7.8
CVE-2026-34642

After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execut…

Fix: 25.6.5+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34343

Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 21h2 HIGH 7.8
CVE-2026-33841

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7291 / 10.0.19045.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 8.8
CVE-2026-34329

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12