Vulnerability index

Browse CVEs

3,242 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Pillow MEDIUM 5.5
CVE-2026-42308

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track …

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Pgbouncer HIGH 7.5
CVE-2026-6664

An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated r…

Fix: 1.25.2+
Fix from $1,950 2026-05-09
Neovim MEDIUM 5.5
CVE-2026-45130

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when …

Fix: 9.2.0450+
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.2
CVE-2026-42199

Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relat…

Patch available
Fix from $1,600 2026-05-08
Openexr CRITICAL 9.8
CVE-2026-42217

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.9 / 3.3.11+
Fix from $2,300 2026-05-07
Openexr HIGH 8.8
CVE-2026-41142

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.9 / 3.3.11+
Fix from $1,950 2026-05-07
Linux Kernel HIGH 7.5
CVE-2026-43254

In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When processing TCP stream data i…

Fix: 6.18.16 / 6.19.6+
Fix from $1,950 2026-05-06
Unclassified MEDIUM 6.1
CVE-2026-42144

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation…

Patch available
Fix from $1,600 2026-05-04
Libssh2 HIGH 7.3
CVE-2026-7598

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c…

Fix: after 1.11.1
Fix from $1,950 2026-05-01
Unclassified HIGH 8.1
CVE-2026-37537

collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-bounds writ…

Mitigation only
Fix from $1,950 2026-05-01
Openamp CRITICAL 9.8
CVE-2026-37540

OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of tw…

Mitigation only
Fix from $2,300 2026-05-01
Frrouting MEDIUM 6.5
CVE-2026-28532

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a…

Fix: 10.5.3+
Fix from $1,600 2026-04-30
Libsndfile HIGH 7.5
CVE-2026-37555

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (l…

Patch available
Fix from $1,950 2026-04-29
Thrift HIGH 7.5
CVE-2026-41602

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.3
CVE-2026-41605

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Pjsip HIGH 7.5
CVE-2026-41416

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buff…

Fix: 2.17+
Fix from $1,950 2026-04-24
Zserio HIGH 7.5
CVE-2026-33666

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readB…

Fix: 2.18.1+
Fix from $1,950 2026-04-24
Op Tee HIGH 7.5
CVE-2026-33662

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-04-24
Linux Kernel HIGH 7.8
CVE-2026-31648

In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() When runn…

Fix: 6.2 / 6.6.135+
Fix from $1,950 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31649

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode imp…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel HIGH 7.8
CVE-2026-31641

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() rea…

Fix: 6.18.23 / 6.19.13+
Fix from $1,950 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31633

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response()…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Go Ntlmssp HIGH 7.5
CVE-2026-32952

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can caus…

Fix: 0.1.1+
Fix from $1,950 2026-04-24
Nimiq Proof Of Stake CRITICAL 9.6
CVE-2026-33471

nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len…

Fix: 1.3.0+
Fix from $2,300 2026-04-22
Dnsdist MEDIUM 6.5
CVE-2026-33596

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly…

Fix: 1.9.13 / 2.0.4+
Fix from $1,600 2026-04-22
Linux Kernel MEDIUM 5.5
CVE-2026-31491

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Harden depth calculation functions An issue was exposed where OS ca…

Fix: 6.18.21 / 6.19.11+
Fix from $1,600 2026-04-22
One MEDIUM 6.6
CVE-2026-40449

Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affec…

Fix: 1.30.0+
Fix from $1,600 2026-04-22
One MEDIUM 6.6
CVE-2026-40450

Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversi…

Fix: 1.30.0+
Fix from $1,600 2026-04-22
One MEDIUM 6.6
CVE-2026-41664

Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affecte…

Fix: 1.30.0+
Fix from $1,600 2026-04-22
One MEDIUM 6.1
CVE-2026-41665

Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large interme…

Fix: 1.30.0+
Fix from $1,600 2026-04-22