Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
MEDIUM 5.9 CVE-2026-58152 Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-55969 Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: b… Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-41602 Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-41605 Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2025-66168 WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https:… Activemq 5.19.2+ Fix from $1,9502026-03-04 HIGH 7.5 CVE-2025-55753 An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the bac… HTTP Server 2.4.66+ Fix from $1,9502025-12-05 HIGH 7.5 CVE-2025-54472 Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi… Brpc 1.14.1+ Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-52520 For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size li… Tomcat 9.0.107 / 10.1.43+ Fix from $1,9502025-07-10 MEDIUM 6.5 CVE-2018-9481 In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d… Traffic Server 7.1.10 / 8.0.7+ Fix from $1,6002024-11-20 HIGH 8.8 CVE-2023-43826 Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user con… Guacamole after 1.5.3 Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-37536 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. Xerces C\+\+ 9.5.23 / 10.0.10+ Fix from $1,9502023-10-11 CRITICAL 9.8 CVE-2022-24963 Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a … Portable Runtime Mitigation only Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2022-28331 On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int… Portable Runtime after 1.7.0 Fix from $2,3002023-01-31 MEDIUM 6.5 CVE-2022-25147 Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond… Portable Runtime Utility after 1.6.1 Fix from $1,6002023-01-31 HIGH 7.5 CVE-2022-36125 It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust … Avro 0.14.0+ Fix from $1,9502022-08-09 CRITICAL 9.1 CVE-2022-28615EPSS 6% Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extrem… HTTP Server 2.4.54+ Fix from $2,3002022-06-09 MEDIUM 5.3 CVE-2022-28614 The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg… HTTP Server after 2.4.53 Fix from $1,6002022-06-09 CRITICAL 9.8 CVE-2022-23943EPSS 50% Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. … HTTP Server 2.4.53+ Fix from $2,3002022-03-14 CRITICAL 9.1 CVE-2022-22721EPSS 42% If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca… HTTP Server 10.15.7 / 11.6.6+ Fix from $2,3002022-03-14 CRITICAL 9.8 CVE-2021-26461EPSS 5% Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen… Nuttx 10.1.0+ Fix from $2,3002021-06-21 HIGH 9.3 CVE-2009-2949EPSS 14% Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to … Openoffice 3.2.0+ Fix from $1,9502010-02-16 HIGH 9.3 CVE-2007-2834EPSS 12% Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack… Openoffice 2.3.0+ Fix from $1,9502007-09-18