Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Chrome HIGH 8.3
CVE-2026-10925

Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10907

Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10897

Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10892

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10881

Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome HIGH 8.8
CVE-2026-10883

Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Zephyr HIGH 8.8
CVE-2026-5066

A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). W…

Fix: after 4.3.0
Fix from $1,950 2026-06-04
Zephyr MEDIUM 6.3
CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-boun…

Fix: after 4.3.0
Fix from $1,600 2026-06-04
Netty Incubator Codec Ohttp CRITICAL 9.1
CVE-2026-48040

The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C libr…

Fix: 0.0.22+
Fix from $2,300 2026-06-04
Unclassified MEDIUM 6.1
CVE-2026-8916

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd76…

Patch available
Fix from $1,600 2026-06-04
Linux Kernel HIGH 7.8
CVE-2026-46253

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_sav…

Fix: 5.10.252 / 5.15.202+
Fix from $1,950 2026-06-03
Unclassified HIGH 8.2
CVE-2021-4478

Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A…

Mitigation only
Fix from $1,950 2026-06-02
Ebpf Instrumentation MEDIUM 5.3
CVE-2026-45684

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI…

Fix: 0.9.0+
Fix from $1,600 2026-06-02
Napoca HIGH 7.8
CVE-2026-10046

Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in…

Mitigation only
Fix from $1,950 2026-06-02
Napoca HIGH 7.8
CVE-2026-10047

The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kerne…

Mitigation only
Fix from $1,950 2026-06-02
Cologne Firmware HIGH 7.8
CVE-2026-25259

Memory corruption while processing multiple IOCTL command for escape operations.

No fix yet
Fix from $1,950 2026-06-01
Aqt1000 Firmware MEDIUM 6.7
CVE-2025-59611

Memory corruption in diagnostic services due to absence of input validation

Mitigation only
Fix from $1,600 2026-06-01
Cologne Firmware MEDIUM 6.7
CVE-2025-59614

Memory Corruption when sending random number generator command with insufficient output buffer size.

No fix yet
Fix from $1,600 2026-06-01
Snapdragon G1 Gen 2 Gaming Platform Firmware HIGH 7.8
CVE-2025-59605

Memory Corruption when processing device identifier strings that exceed the expected maximum length.

Mitigation only
Fix from $1,950 2026-06-01
Mt6739 Firmware HIGH 7.8
CVE-2026-20455

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …

Mitigation only
Fix from $1,950 2026-06-01
Mt7902 Firmware MEDIUM 5.5
CVE-2026-20456

In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution pr…

Mitigation only
Fix from $1,600 2026-06-01
Mt8673 Firmware MEDIUM 6.7
CVE-2026-20453

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …

Mitigation only
Fix from $1,600 2026-06-01
Freerdp CRITICAL 9.8
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write whe…

Fix: 3.26.0+
Fix from $2,300 2026-05-29
Freerdp HIGH 8.8
CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in …

Fix: 3.26.0+
Fix from $1,950 2026-05-29
Chrome HIGH 8.8
CVE-2026-9973

Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9974

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9975

Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9965

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9967

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome HIGH 8.8
CVE-2026-9910

Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox vi…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28