Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Apr Util HIGH 7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1…

Fix: 1.6.4+
Fix from $1,950 2026-08-06
Apr Util HIGH 7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro…

Fix: after 1.6.3
Fix from $1,950 2026-08-06
Thrift CRITICAL 9.8
CVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
HTTP Server HIGH 7.5
CVE-2026-42536

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTT…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server HIGH 7.5
CVE-2026-34355

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgra…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server HIGH 7.5
CVE-2026-34356

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache …

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
Nuttx CRITICAL 9.8
CVE-2025-47868

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Orc CRITICAL 9.8
CVE-2025-47436

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially …

Fix: 1.8.9 / 1.9.6+
Fix from $2,300 2025-05-14
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10