Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
HIGH 7.8 CVE-2026-33837 Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-32177 Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Visual Studio 2022 8.0.27 / 9.0.16+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2025-12659 Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute… Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-42046 libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows … Patch available Fix from $1,9502026-05-11 HIGH 8.4 CVE-2026-4892 A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root pri… Patch available Fix from $1,9502026-05-11 MEDIUM 5.9 CVE-2026-8261 A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipul… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.5 CVE-2026-8212 A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWap… Gdal after 3.12.4 Fix from $1,6002026-05-09 MEDIUM 5.5 CVE-2026-8213 A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDa… Gdal after 3.12.4 Fix from $1,6002026-05-09 MEDIUM 5.5 CVE-2026-42309 Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates… Pillow 12.2.0+ Fix from $1,6002026-05-09 MEDIUM 5.5 CVE-2026-45130 Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when … Neovim 9.2.0450+ Fix from $1,6002026-05-08 CRITICAL 9.8 CVE-2026-41509 CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there i… Cross Implementation 2026-03-23+ Fix from $2,3002026-05-08 HIGH 7.8 CVE-2026-8087 A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Perf… Gdal after 3.12.4 Fix from $1,9502026-05-07 HIGH 7.8 CVE-2026-8086 A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Su… Gdal after 3.12.4 Fix from $1,9502026-05-07 HIGH 8.3 CVE-2026-7900 Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potential… Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 HIGH 7.7 CVE-2026-20185 A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series St… Mitigation only Fix from $1,9502026-05-06 HIGH 8.7 CVE-2026-6210 A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker refe… Mitigation only Fix from $1,9502026-05-06 CRITICAL 9.8 CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server … HTTP Server 2.4.67+ Fix from $2,3002026-05-05 HIGH 8.8 CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values… Redis 8.6.3+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-25588 RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialize… Redistimeseries 1.12.14+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-25589 RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate se… Redisbloom 2.8.20+ Fix from $1,9502026-05-05 MEDIUM 5.5 CVE-2026-39103 Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the… Gpac 2026-04-01+ Fix from $1,6002026-05-05 HIGH 8.1 CVE-2026-29004 BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/u… Patch available Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2025-70067 Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, w… Mitigation only Fix from $2,3002026-05-04 HIGH 7.1 CVE-2026-42477 A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-a… Open Cascade Technology after 7.9.3 Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-42483 A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitr… Hashcat Mitigation only Fix from $2,3002026-05-01 HIGH 7.8 CVE-2026-5403 SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-5405 RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-05-01 HIGH 8.1 CVE-2026-35547 When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious pro… FreeBSD Mitigation only Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-42512 As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the ar… FreeBSD Mitigation only Fix from $1,9502026-04-30 MEDIUM 5.5 CVE-2026-6529 iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30