Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
HIGH 8.8 CVE-2026-3556 Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta… Hue Bridge V2 Firmware 1975170000+ Fix from $1,9502026-03-16 HIGH 8.0 CVE-2026-3557 Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows … Hue Bridge V2 Firmware 1975170000+ Fix from $1,9502026-03-16 HIGH 7.8 CVE-2026-3082 GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Gstreamer 1.28.1+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-3085 GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Gstreamer 1.28.1+ Fix from $1,9502026-03-16 HIGH 7.8 CVE-2026-2920 GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Gstreamer 1.28.1+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-28519 arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local a… Arduino Tuyaopen 1.2.1+ Fix from $1,9502026-03-16 HIGH 7.7 CVE-2025-10685 Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflo… Mitigation only Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-31883 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders lea… Freerdp 3.24.0+ Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND mes… Freerdp 3.24.0+ Fix from $2,3002026-03-13 MEDIUM 6.5 CVE-2025-61154 Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) … Libredwg after 0.13.3.7835 Fix from $1,6002026-03-12 HIGH 7.8 CVE-2026-27940 llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer over… Llama.cpp No fix yet Fix from $1,9502026-03-12 MEDIUM 5.3 CVE-2026-3994 A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the fi… Mitigation only Fix from $1,6002026-03-12 HIGH 8.8 CVE-2026-3931 Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted H… Chrome 146.0.7680.71+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-3913 Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 146.0.7680.71+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-3915 Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted… Chrome 146.0.7680.71+ Fix from $1,9502026-03-11 MEDIUM 6.1 CVE-2026-1652 A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated … Mitigation only Fix from $1,6002026-03-11 MEDIUM 5.5 CVE-2026-31853 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit… Imagemagick 6.9.13-41 / 7.1.2-16+ Fix from $1,6002026-03-11 HIGH 7.8 CVE-2026-27271 Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code executio… Illustrator 29.8.5 / 30.2+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-3845 Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2. Firefox 148.0.2+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-31796 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow … Iccdev 2.3.1.5+ Fix from $1,9502026-03-10 MEDIUM 6.1 CVE-2026-30982 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in … Iccdev 2.3.1.5+ Fix from $1,6002026-03-10 HIGH 7.8 CVE-2026-30985 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow … Iccdev 2.3.1.5+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-30979 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow … Iccdev 2.3.1.5+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26108 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-26111 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2012 6.2.9200.25973 / 10.0.14393.8957+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-25188 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-25172 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-25173 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-24283 Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.2207 / 10.0.26100.7979+ Fix from $1,9502026-03-10 MEDIUM 6.8 CVE-2026-24288 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. Windows 10 21h2 10.0.19044.7058 / 10.0.19045.7058+ Fix from $1,6002026-03-10