Vulnerability index

Browse CVEs

3,242 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
MEDIUM 5.5 CVE-2026-42308 Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track … Pillow 12.2.0+ Fix from $1,6002026-05-09 HIGH 7.5 CVE-2026-6664 An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated r… Pgbouncer 1.25.2+ Fix from $1,9502026-05-09 MEDIUM 5.5 CVE-2026-45130 Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when … Neovim 9.2.0450+ Fix from $1,6002026-05-08 MEDIUM 6.2 CVE-2026-42199 Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relat… Patch available Fix from $1,6002026-05-08 CRITICAL 9.8 CVE-2026-42217 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From… Openexr 3.2.9 / 3.3.11+ Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-41142 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From… Openexr 3.2.9 / 3.3.11+ Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-43254 In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When processing TCP stream data i… Linux Kernel 6.18.16 / 6.19.6+ Fix from $1,9502026-05-06 MEDIUM 6.1 CVE-2026-42144 CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation… Patch available Fix from $1,6002026-05-04 HIGH 7.3 CVE-2026-7598 A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c… Libssh2 after 1.11.1 Fix from $1,9502026-05-01 HIGH 8.1 CVE-2026-37537 collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-bounds writ… Mitigation only Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-37540 OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of tw… Openamp Mitigation only Fix from $2,3002026-05-01 MEDIUM 6.5 CVE-2026-28532 FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a… Frrouting 10.5.3+ Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-37555 An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (l… Libsndfile Patch available Fix from $1,9502026-04-29 HIGH 7.5 CVE-2026-41602 Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-41605 Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-41416 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buff… Pjsip 2.17+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-33666 Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readB… Zserio 2.18.1+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-33662 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone… Op Tee after 4.10.0 Fix from $1,9502026-04-24 HIGH 7.8 CVE-2026-31648 In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() When runn… Linux Kernel 6.2 / 6.6.135+ Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-31649 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode imp… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-24 HIGH 7.8 CVE-2026-31641 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() rea… Linux Kernel 6.18.23 / 6.19.13+ Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-31633 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response()… Linux Kernel 6.18.23 / 6.19.13+ Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-32952 go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can caus… Go Ntlmssp 0.1.1+ Fix from $1,9502026-04-24 CRITICAL 9.6 CVE-2026-33471 nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len… Nimiq Proof Of Stake 1.3.0+ Fix from $2,3002026-04-22 MEDIUM 6.5 CVE-2026-33596 A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-31491 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Harden depth calculation functions An issue was exposed where OS ca… Linux Kernel 6.18.21 / 6.19.11+ Fix from $1,6002026-04-22 MEDIUM 6.6 CVE-2026-40449 Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affec… One 1.30.0+ Fix from $1,6002026-04-22 MEDIUM 6.6 CVE-2026-40450 Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversi… One 1.30.0+ Fix from $1,6002026-04-22 MEDIUM 6.6 CVE-2026-41664 Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affecte… One 1.30.0+ Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2026-41665 Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large interme… One 1.30.0+ Fix from $1,6002026-04-22