Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3556

Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3557

Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Gstreamer HIGH 7.8
CVE-2026-3082

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Fix: 1.28.1+
Fix from $1,950 2026-03-16
Gstreamer HIGH 8.8
CVE-2026-3085

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 1.28.1+
Fix from $1,950 2026-03-16
Gstreamer HIGH 7.8
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Fix: 1.28.1+
Fix from $1,950 2026-03-16
Arduino Tuyaopen HIGH 8.8
CVE-2026-28519

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local a…

Fix: 1.2.1+
Fix from $1,950 2026-03-16
Unclassified HIGH 7.7
CVE-2025-10685

Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflo…

Mitigation only
Fix from $1,950 2026-03-16
Freerdp CRITICAL 9.8
CVE-2026-31883

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders lea…

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.8
CVE-2026-31806

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND mes…

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Libredwg MEDIUM 6.5
CVE-2025-61154

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) …

Fix: after 0.13.3.7835
Fix from $1,600 2026-03-12
Llama.cpp HIGH 7.8
CVE-2026-27940

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer over…

No fix yet
Fix from $1,950 2026-03-12
Unclassified MEDIUM 5.3
CVE-2026-3994

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the fi…

Mitigation only
Fix from $1,600 2026-03-12
Chrome HIGH 8.8
CVE-2026-3931

Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted H…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3913

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3915

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Unclassified MEDIUM 6.1
CVE-2026-1652

A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated …

Mitigation only
Fix from $1,600 2026-03-11
Imagemagick MEDIUM 5.5
CVE-2026-31853

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit…

Fix: 6.9.13-41 / 7.1.2-16+
Fix from $1,600 2026-03-11
Illustrator HIGH 7.8
CVE-2026-27271

Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code executio…

Fix: 29.8.5 / 30.2+
Fix from $1,950 2026-03-10
Firefox HIGH 8.8
CVE-2026-3845

Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2.

Fix: 148.0.2+
Fix from $1,950 2026-03-10
Iccdev HIGH 7.8
CVE-2026-31796

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow …

Fix: 2.3.1.5+
Fix from $1,950 2026-03-10
Iccdev MEDIUM 6.1
CVE-2026-30982

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in …

Fix: 2.3.1.5+
Fix from $1,600 2026-03-10
Iccdev HIGH 7.8
CVE-2026-30985

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow …

Fix: 2.3.1.5+
Fix from $1,950 2026-03-10
Iccdev HIGH 7.8
CVE-2026-30979

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow …

Fix: 2.3.1.5+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26108

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
Windows Server 2012 HIGH 8.0
CVE-2026-26111

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 6.2.9200.25973 / 10.0.14393.8957+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 8.8
CVE-2026-25188

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows Server 2012 HIGH 8.0
CVE-2026-25172

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 8.0
CVE-2026-25173

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 24h2 HIGH 8.8
CVE-2026-24283

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.2207 / 10.0.26100.7979+
Fix from $1,950 2026-03-10
Windows 10 21h2 MEDIUM 6.8
CVE-2026-24288

Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.

Fix: 10.0.19044.7058 / 10.0.19045.7058+
Fix from $1,600 2026-03-10