Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 8.3 CVE-2026-10925 Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10907 Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted H… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10897 Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 CRITICAL 9.6 CVE-2026-10892 Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 149.0.7827.53+ Fix from $2,3002026-06-04 CRITICAL 9.6 CVE-2026-10881 Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 149.0.7827.53+ Fix from $2,3002026-06-04 HIGH 8.8 CVE-2026-10883 Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-5066 A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). W… Zephyr after 4.3.0 Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2026-5589 An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-boun… Zephyr after 4.3.0 Fix from $1,6002026-06-04 CRITICAL 9.1 CVE-2026-48040 The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C libr… Netty Incubator Codec Ohttp 0.0.22+ Fix from $2,3002026-06-04 MEDIUM 6.1 CVE-2026-8916 Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd76… Patch available Fix from $1,6002026-06-04 HIGH 7.8 CVE-2026-46253 In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_sav… Linux Kernel 5.10.252 / 5.15.202+ Fix from $1,9502026-06-03 HIGH 8.2 CVE-2021-4478 Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A… Mitigation only Fix from $1,9502026-06-02 MEDIUM 5.3 CVE-2026-45684 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI… Ebpf Instrumentation 0.9.0+ Fix from $1,6002026-06-02 HIGH 7.8 CVE-2026-10046 Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in… Napoca Mitigation only Fix from $1,9502026-06-02 HIGH 7.8 CVE-2026-10047 The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kerne… Napoca Mitigation only Fix from $1,9502026-06-02 HIGH 7.8 CVE-2026-25259 Memory corruption while processing multiple IOCTL command for escape operations. Cologne Firmware No fix yet Fix from $1,9502026-06-01 MEDIUM 6.7 CVE-2025-59611 Memory corruption in diagnostic services due to absence of input validation Aqt1000 Firmware Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.7 CVE-2025-59614 Memory Corruption when sending random number generator command with insufficient output buffer size. Cologne Firmware No fix yet Fix from $1,6002026-06-01 HIGH 7.8 CVE-2025-59605 Memory Corruption when processing device identifier strings that exceed the expected maximum length. Snapdragon G1 Gen 2 Gaming Platform Firmware Mitigation only Fix from $1,9502026-06-01 HIGH 7.8 CVE-2026-20455 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious … Mt6739 Firmware Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.5 CVE-2026-20456 In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution pr… Mt7902 Firmware Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.7 CVE-2026-20453 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious … Mt8673 Firmware Mitigation only Fix from $1,6002026-06-01 CRITICAL 9.8 CVE-2026-45700 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write whe… Freerdp 3.26.0+ Fix from $2,3002026-05-29 HIGH 8.8 CVE-2026-44421 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in … Freerdp 3.26.0+ Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-9973 Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9974 Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9975 Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9965 Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 CRITICAL 9.6 CVE-2026-9967 Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-9910 Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox vi… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28