Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Gimp HIGH 8.8
CVE-2026-0797

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2026-02-20
Pjsip MEDIUM 5.3
CVE-2026-26967

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Over…

Fix: 2.17+
Fix from $1,600 2026-02-20
Hdf5 HIGH 7.8
CVE-2026-26200

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap…

Fix: 1.14.4.2+
Fix from $1,950 2026-02-19
Chrome HIGH 8.8
CVE-2026-2648

Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a craf…

Fix: 145.0.7632.109+
Fix from $1,950 2026-02-18
Chrome HIGH 8.8
CVE-2026-2650

Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 145.0.7632.109+
Fix from $1,950 2026-02-18
Squirrel HIGH 7.8
CVE-2026-2661

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The ma…

Fix: after 3.2
Fix from $1,950 2026-02-18
Admesh HIGH 7.8
CVE-2026-2653

A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Perfor…

Fix: after 0.98.5
Fix from $1,950 2026-02-18
Crypt\ HIGH 7.5
CVE-2026-2474

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The fun…

Fix: 0.55+
Fix from $1,950 2026-02-16
Firefox HIGH 8.8
CVE-2026-2447

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and …

Fix: 115.32.1 / 140.7.1+
Fix from $1,950 2026-02-16
Free5gc HIGH 7.5
CVE-2025-70122

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP S…

No fix yet
Fix from $1,950 2026-02-13
Unclassified CRITICAL 9.8
CVE-2019-25327

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $2,300 2026-02-12
Nav2 CRITICAL 9.8
CVE-2026-26011

navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL'…

Fix: after 1.3.11
Fix from $2,300 2026-02-12
Unclassified HIGH 7.5
CVE-2025-67433

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via …

Mitigation only
Fix from $1,950 2026-02-12
PostgreSQL HIGH 8.8
CVE-2026-2005

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.…

Fix: 14.21 / 15.16+
Fix from $1,950 2026-02-12
PostgreSQL HIGH 8.2
CVE-2026-2007

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited co…

Fix: 18.2+
Fix from $1,950 2026-02-12
Chrome HIGH 8.8
CVE-2026-2314

Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 145.0.7632.45+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-57709

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-52868

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-52869

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-52870

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-48723

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Qsync Central HIGH 8.1
CVE-2025-48724

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.0.0.4+
Fix from $1,950 2026-02-11
Libpng HIGH 8.1
CVE-2026-25646

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to …

Fix: 1.6.55+
Fix from $1,950 2026-02-10
Indesign HIGH 7.8
CVE-2026-21357

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe…

Fix: 20.5.2 / 21.2+
Fix from $1,950 2026-02-10
Indesign MEDIUM 5.5
CVE-2026-21358

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial…

Fix: 20.5.2 / 21.2+
Fix from $1,600 2026-02-10
365 Apps HIGH 7.8
CVE-2026-21259

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

Fix: 16.0.10417.20097+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21246

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21247

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21248

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21244

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10