Vulnerability index

Browse CVEs

2,635 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
HIGH 8.8 CVE-2026-56002 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec… Libxfont 2.0.8+ Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-56003 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf… Libxfont 2.0.8+ Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the… Libxfont 2.0.8+ Fix from $1,9502026-07-08 HIGH 7.8 CVE-2026-55999 Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a … X Server 21.2.24 / 24.1.13+ Fix from $1,9502026-07-08 HIGH 7.1 CVE-2026-58471 GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that… Wget after 1.25.0 Fix from $1,9502026-07-07 MEDIUM 5.3 CVE-2026-14940 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted… Directory Server Mitigation only Fix from $1,6002026-07-07 HIGH 8.8 CVE-2026-11610 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protec… Mitigation only Fix from $1,9502026-07-07 HIGH 7.8 CVE-2026-14759 A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the … Radare2 6.1.8+ Fix from $1,9502026-07-05 HIGH 8.8 CVE-2026-56645 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 MEDIUM 5.3 CVE-2026-14610 A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/… Patch available Fix from $1,6002026-07-03 MEDIUM 5.3 CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenS… PHP 8.2.32 / 8.3.32+ Fix from $1,6002026-07-03 HIGH 7.3 CVE-2026-58379 A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitra… Mitigation only Fix from $1,9502026-07-03 HIGH 8.3 CVE-2026-14427 Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentiall… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14415 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI ge… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14385 Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a c… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 MEDIUM 5.3 CVE-2025-15666 A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::Sc… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.7 CVE-2026-20462 In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious ac… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.8 CVE-2026-13976 Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-13884 Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traff… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-13835 Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 CRITICAL 9.6 CVE-2026-13798 Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to pote… Chrome 150.0.7871.46+ Fix from $2,3002026-06-30 HIGH 7.5 CVE-2026-51218 A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of … Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-51219 A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial … Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.6 CVE-2026-13590 A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/head… Patch available Fix from $1,6002026-06-29 HIGH 7.3 CVE-2026-12912 A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This… Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.6 CVE-2026-13588 A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of… Patch available Fix from $1,6002026-06-29 MEDIUM 5.6 CVE-2026-13589 A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/Teln… Patch available Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-30040 A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the c… Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-56789 RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory… Rtklib after 2.4.3 Fix from $1,6002026-06-25 CRITICAL 9.8 CVE-2026-56123 socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite ad… Socat 1.8.1.2+ Fix from $2,3002026-06-25