Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
macOS HIGH 7.5
CVE-2026-28842

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and u…

Fix: 26.4+
Fix from $1,950 2026-03-25
Nginx Plus HIGH 8.2
CVE-2026-27654EPSS 22%

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to …

Fix: 1.28.3 / 1.29.7+
Fix from $1,950 2026-03-24
Chrome HIGH 8.8
CVE-2026-4675

Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafte…

Fix: 146.0.7680.164+
Fix from $1,950 2026-03-24
Chrome HIGH 8.8
CVE-2026-4673

Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a cr…

Fix: 146.0.7680.164+
Fix from $1,950 2026-03-24
Llama.cpp HIGH 7.8
CVE-2026-33298

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an a…

No fix yet
Fix from $1,950 2026-03-24
Libde265 HIGH 7.5
CVE-2026-33164

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fau…

Fix: 1.0.17+
Fix from $1,950 2026-03-20
MariaDB CRITICAL 9.9
CVE-2026-32710

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11…

Fix: 11.4.10 / 11.8.6+
Fix from $2,300 2026-03-20
Pjsip CRITICAL 9.8
CVE-2026-32945

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability…

Fix: 2.17+
Fix from $2,300 2026-03-20
Chrome HIGH 8.8
CVE-2026-4463

Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4455

Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4448

Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4442

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4443

Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Wolfssl CRITICAL 9.8
CVE-2026-4395

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-cont…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Wolfssl MEDIUM 5.5
CVE-2026-3229

An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written …

Fix: 5.9.0+
Fix from $1,600 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-3549

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Wolfssl HIGH 8.1
CVE-2026-2646

A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabl…

Fix: 5.9.0+
Fix from $1,950 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-3548

Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when imprope…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Xml\ CRITICAL 9.8
CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the s…

Fix: 2.48+
Fix from $2,300 2026-03-19
Xml\ HIGH 7.5
CVE-2006-10002

XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crash…

Fix: 2.48+
Fix from $1,950 2026-03-19
Htslib HIGH 8.1
CVE-2026-31971

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 8.1
CVE-2026-31968

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 8.1
CVE-2026-31969

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 8.1
CVE-2026-31970

HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI …

Fix: 1.21 / 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 8.1
CVE-2026-31963

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 8.8
CVE-2026-31962

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While …

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Yaml\ CRITICAL 9.1
CVE-2026-4177

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML e…

Fix: 1.37+
Fix from $2,300 2026-03-16
Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3560

Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3561

Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3555

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netw…

Fix: 1975170000+
Fix from $1,950 2026-03-16