Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Traffic Server MEDIUM 5.9
CVE-2026-58152

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.…

Fix: 9.2.15 / 10.1.4+
Fix from $1,600 2026-07-29
Thrift HIGH 7.5
CVE-2026-55969

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: b…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-41602

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.3
CVE-2026-41605

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Activemq HIGH 8.8
CVE-2025-66168

WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https:…

Fix: 5.19.2+
Fix from $1,950 2026-03-04
HTTP Server HIGH 7.5
CVE-2025-55753

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the bac…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
Brpc HIGH 7.5
CVE-2025-54472

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…

Fix: 1.14.1+
Fix from $1,950 2025-08-14
Tomcat HIGH 7.5
CVE-2025-52520

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size li…

Fix: 9.0.107 / 10.1.43+
Fix from $1,950 2025-07-10
Traffic Server MEDIUM 6.5
CVE-2018-9481

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d…

Fix: 7.1.10 / 8.0.7+
Fix from $1,600 2024-11-20
Guacamole HIGH 8.8
CVE-2023-43826

Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user con…

Fix: after 1.5.3
Fix from $1,950 2023-12-19
Xerces C\+\+ HIGH 8.8
CVE-2023-37536

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Fix: 9.5.23 / 10.0.10+
Fix from $1,950 2023-10-11
Portable Runtime CRITICAL 9.8
CVE-2022-24963

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …

Mitigation only
Fix from $2,300 2023-01-31
Portable Runtime CRITICAL 9.8
CVE-2022-28331

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…

Fix: after 1.7.0
Fix from $2,300 2023-01-31
Portable Runtime Utility MEDIUM 6.5
CVE-2022-25147

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond…

Fix: after 1.6.1
Fix from $1,600 2023-01-31
Avro HIGH 7.5
CVE-2022-36125

It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust …

Fix: 0.14.0+
Fix from $1,950 2022-08-09
HTTP Server CRITICAL 9.1
CVE-2022-28615EPSS 6%

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extrem…

Fix: 2.4.54+
Fix from $2,300 2022-06-09
HTTP Server MEDIUM 5.3
CVE-2022-28614

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg…

Fix: after 2.4.53
Fix from $1,600 2022-06-09
HTTP Server CRITICAL 9.8
CVE-2022-23943EPSS 50%

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …

Fix: 2.4.53+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.1
CVE-2022-22721EPSS 42%

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca…

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
Nuttx CRITICAL 9.8
CVE-2021-26461EPSS 5%

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen…

Fix: 10.1.0+
Fix from $2,300 2021-06-21
Openoffice HIGH 9.3
CVE-2009-2949EPSS 14%

Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to …

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Openoffice HIGH 9.3
CVE-2007-2834EPSS 12%

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…

Fix: 2.3.0+
Fix from $1,950 2007-09-18