Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
HIGH 7.3 CVE-2025-70103 Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc. Patch available Fix from $1,9502026-05-27 CRITICAL 9.8 CVE-2026-8175 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $2,3002026-05-27 HIGH 7.3 CVE-2026-38427 An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Lengt… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-9605 A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utili… Patch available Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-44983 smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of s… Mitigation only Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-48689 FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary… Fastnetmon after 1.2.9 Fix from $2,3002026-05-26 HIGH 8.0 CVE-2026-8834 IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 HIGH 7.1 CVE-2026-48690 FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.… Fastnetmon after 1.2.9 Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-48691 FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4Unicas… Fastnetmon after 1.2.9 Fix from $2,3002026-05-26 HIGH 8.8 CVE-2026-40033 FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap me… Freerdp 3.26.0+ Fix from $1,9502026-05-26 MEDIUM 5.3 CVE-2026-9541 A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnu… Squirrel after 3.2 Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-48135 A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. No fix yet Fix from $1,6002026-05-26 HIGH 8.1 CVE-2026-48131 The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This … Mitigation only Fix from $1,9502026-05-26 HIGH 7.8 CVE-2026-25713 MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability Mediainfolib No fix yet Fix from $1,9502026-05-26 MEDIUM 5.3 CVE-2026-9500 A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of t… Mitigation only Fix from $1,6002026-05-25 MEDIUM 5.3 CVE-2026-9502 A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the compone… Patch available Fix from $1,6002026-05-25 MEDIUM 5.6 CVE-2026-9365 A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the c… Patch available Fix from $1,6002026-05-24 HIGH 8.1 CVE-2026-9256EPSS 10% NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses … Nginx Open Source 1.30.2 / 2.6.2+ Fix from $1,9502026-05-22 MEDIUM 5.5 CVE-2026-45252 When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list o… FreeBSD Mitigation only Fix from $1,6002026-05-21 CRITICAL 9.9 CVE-2026-44050 A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute… Mitigation only Fix from $2,3002026-05-21 MEDIUM 6.5 CVE-2026-9149 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat… Hardened Images after 0.7.36 Fix from $1,6002026-05-21 CRITICAL 9.8 CVE-2026-8631 A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati… Linux Imaging And Printing 3.26.4+ Fix from $2,3002026-05-20 HIGH 7.5 CVE-2026-9123 Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary… Chrome 148.0.7778.179+ Fix from $1,9502026-05-20 HIGH 8.8 CVE-2026-9119 Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 148.0.7778.178+ Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-22554 MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability Mediainfolib Mitigation only Fix from $1,9502026-05-20 HIGH 8.1 CVE-2026-45584 Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 HIGH 7.1 CVE-2026-32741 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_i… Mitigation only Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-33633 Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process w… Kitty 0.47.0+ Fix from $1,9502026-05-19 CRITICAL 9.8 CVE-2026-8711 NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,… Njs 0.9.9+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-47311 Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da85… Escargot Patch available Fix from $2,3002026-05-19