Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Wireshark MEDIUM 5.5
CVE-2026-6530

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark HIGH 7.5
CVE-2026-5653

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,950 2026-04-30
Wireshark HIGH 8.8
CVE-2026-5402

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Fix: after 4.6.4
Fix from $1,950 2026-04-30
Wireshark HIGH 7.5
CVE-2026-7378

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-04-30
Chrome HIGH 8.3
CVE-2026-7353

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 147.0.7727.138+
Fix from $1,950 2026-04-28
Chrome HIGH 8.8
CVE-2026-7339

Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 147.0.7727.138+
Fix from $1,950 2026-04-28
Unclassified HIGH 8.8
CVE-2026-20766

An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.

Mitigation only
Fix from $1,950 2026-04-28
Text\ HIGH 7.5
CVE-2026-7040

Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify function…

Fix: 0.7.8+
Fix from $1,950 2026-04-27
Dnsdist HIGH 8.2
CVE-2026-33602

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Hardened Images HIGH 7.8
CVE-2026-6846

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form…

Fix: after 2.46
Fix from $1,950 2026-04-22
Unclassified HIGH 8.4
CVE-2026-40706

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt h…

Mitigation only
Fix from $1,950 2026-04-21
Pjsip HIGH 8.8
CVE-2026-40614

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus aud…

Fix: 2.17+
Fix from $1,950 2026-04-21
Glibc CRITICAL 9.8
CVE-2026-5450

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec…

Fix: after 2.43
Fix from $2,300 2026-04-20
Nanomq HIGH 7.5
CVE-2026-32135

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in t…

Fix: 0.24.11+
Fix from $1,950 2026-04-20
Unclassified HIGH 8.8
CVE-2026-41445

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation si…

Patch available
Fix from $1,950 2026-04-20
Sd 330ac Firmware MEDIUM 5.3
CVE-2026-32961

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. …

Fix: 1.50 / 5.1.0+
Fix from $1,600 2026-04-20
Sd 330ac Firmware CRITICAL 9.8
CVE-2026-32956

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbit…

Fix: 1.50 / 5.1.0+
Fix from $2,300 2026-04-20
Xrdp HIGH 8.8
CVE-2026-35512

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implement…

Fix: 0.10.6+
Fix from $1,950 2026-04-17
Xrdp MEDIUM 6.5
CVE-2026-32624

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environment…

Fix: 0.10.6+
Fix from $1,600 2026-04-17
Xrdp HIGH 8.1
CVE-2026-32623

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxyin…

Fix: 0.10.6+
Fix from $1,950 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-6491

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified CRITICAL 9.8
CVE-2026-40504

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bou…

Patch available
Fix from $2,300 2026-04-16
Chrome HIGH 8.3
CVE-2026-6361

Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specif…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6305

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6306

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome CRITICAL 9.6
CVE-2026-6296

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 147.0.7727.101+
Fix from $2,300 2026-04-15
Framemaker MEDIUM 5.5
CVE-2026-27301

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attack…

Fix: 2022.9+
Fix from $1,600 2026-04-14
Framemaker HIGH 7.8
CVE-2026-27293

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution…

Fix: 2022.9+
Fix from $1,950 2026-04-14
Libsixel HIGH 7.1
CVE-2026-33020

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a …

Fix: 1.8.7-r1+
Fix from $1,950 2026-04-14
Bridge HIGH 7.8
CVE-2026-34630

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i…

Fix: 15.1.5 / 16.0.3+
Fix from $1,950 2026-04-14