Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
MEDIUM 5.5 CVE-2026-6530 DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-5653 DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-5402 TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution Wireshark after 4.6.4 Fix from $1,9502026-04-30 HIGH 7.5 CVE-2026-7378 Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-04-30 HIGH 8.3 CVE-2026-7353 Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potential… Chrome 147.0.7727.138+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2026-7339 Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafte… Chrome 147.0.7727.138+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2026-20766 An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. Mitigation only Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-7040 Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify function… Text\ 0.7.8+ Fix from $1,9502026-04-27 HIGH 8.2 CVE-2026-33602 A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.8 CVE-2026-6846 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form… Hardened Images after 2.46 Fix from $1,9502026-04-22 HIGH 8.4 CVE-2026-40706 In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt h… Mitigation only Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-40614 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus aud… Pjsip 2.17+ Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-5450 Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec… Glibc after 2.43 Fix from $2,3002026-04-20 HIGH 7.5 CVE-2026-32135 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in t… Nanomq 0.24.11+ Fix from $1,9502026-04-20 HIGH 8.8 CVE-2026-41445 KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation si… Patch available Fix from $1,9502026-04-20 MEDIUM 5.3 CVE-2026-32961 SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. … Sd 330ac Firmware 1.50 / 5.1.0+ Fix from $1,6002026-04-20 CRITICAL 9.8 CVE-2026-32956 SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbit… Sd 330ac Firmware 1.50 / 5.1.0+ Fix from $2,3002026-04-20 HIGH 8.8 CVE-2026-35512 xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implement… Xrdp 0.10.6+ Fix from $1,9502026-04-17 MEDIUM 6.5 CVE-2026-32624 xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environment… Xrdp 0.10.6+ Fix from $1,6002026-04-17 HIGH 8.1 CVE-2026-32623 xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxyin… Xrdp 0.10.6+ Fix from $1,9502026-04-17 MEDIUM 5.3 CVE-2026-6491 A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated… Mitigation only Fix from $1,6002026-04-17 CRITICAL 9.8 CVE-2026-40504 Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bou… Patch available Fix from $2,3002026-04-16 HIGH 8.3 CVE-2026-6361 Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specif… Chrome 147.0.7727.101+ Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-6305 Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr… Chrome 147.0.7727.101+ Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-6306 Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr… Chrome 147.0.7727.101+ Fix from $1,9502026-04-15 CRITICAL 9.6 CVE-2026-6296 Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte… Chrome 147.0.7727.101+ Fix from $2,3002026-04-15 MEDIUM 5.5 CVE-2026-27301 Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attack… Framemaker 2022.9+ Fix from $1,6002026-04-14 HIGH 7.8 CVE-2026-27293 Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution… Framemaker 2022.9+ Fix from $1,9502026-04-14 HIGH 7.1 CVE-2026-33020 libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a … Libsixel 1.8.7-r1+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-34630 Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i… Bridge 15.1.5 / 16.0.3+ Fix from $1,9502026-04-14