By weakness (CWE)

CWE-122: related vulnerabilities

CVEs classified under CWE-122. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

141 published vulnerabilities · page 1 of 2

  • CVE-2026-0132HIGH 8.8

    A heap buffer overflow vulnerability exists in the modem component affecting Google Android devices. An attacker with local network access or authenticated privileges can trigger an out-of-bounds memory write that potentially allows arbitrary code execution on the device. No user interaction is required for exploitation, making this a serious threat to affected Android systems.

  • CVE-2026-0149HIGH 8.8

    CVE-2026-0149 is a heap buffer overflow vulnerability in Android's RTP (Real-time Transport Protocol) session handling code. An attacker with local network access and basic authentication credentials can send a specially crafted RTCP packet that causes the RtpSendRtcpPacket function to write beyond allocated memory boundaries. This out-of-bounds write allows arbitrary code execution with the privileges of the affected process, requiring no user interaction or additional escalation. The vulnerability affects authenticated attackers on the same network as the target device.

  • CVE-2026-10989HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to corrupt memory on a victim's computer through a specially crafted web page, but only if the user performs specific interactions with the page. The vulnerability requires user action and comes from an inappropriate implementation in Chrome versions before 149.0.7827.53. Once exploited, an attacker could read sensitive data, modify files, or crash the browser.

  • CVE-2026-10995HIGH 8.8

    A heap buffer overflow vulnerability exists in Google Chrome's TabStrip component that could allow an attacker to corrupt memory on a user's system. The attack requires convincing a user to perform specific gestures while viewing a malicious webpage. While Chromium's maintainers classified this as medium severity, the actual impact—potential code execution with high integrity and confidentiality compromise—warrants close attention from security teams.

  • CVE-2026-11124HIGH 8.8

    A memory handling flaw in Chrome's Skia graphics library allows attackers to trigger heap corruption by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges and works across all major operating systems where Chrome runs. An attacker could achieve code execution with full system access—reading files, modifying data, installing malware, or pivoting to other systems.

  • CVE-2026-11610HIGH 8.8

    A heap buffer overflow vulnerability exists in 389 Directory Server's SASL authentication layer. After an authenticated user successfully logs in with integrity protection enabled, they can send a malformed LDAP packet that causes the server to write up to 2 megabytes of data into a 512-byte memory buffer. This memory corruption crashes the server. In FreeIPA and Red Hat Identity Management environments, any domain user, enrolled host, or service account with valid credentials can exploit this over the network to cause an outage.

  • CVE-2026-12244HIGH 8.8

    NSD, the authoritative DNS server from NLnet Labs, contains a critical vulnerability in how it processes zone transfers from a primary DNS server. When configured as a secondary server, NSD can be crashed and potentially exploited for remote code execution if an attacker controls the primary server and sends a specially crafted DNS SVCB record during a zone transfer. The vulnerability stems from an integer overflow in a variable used to allocate memory for the record, allowing an attacker to write up to 65,509 bytes to heap memory.

  • CVE-2026-12447HIGH 8.8

    A vulnerability in Google Chrome's WebRTC component allows attackers to crash the browser or run malicious code within Chrome's sandbox protection by tricking users into visiting a specially crafted website. The attack requires user interaction—specifically, a user must open or be redirected to the malicious page—but no special privileges are needed on the target system. While the code execution is limited to the Chrome sandbox environment, successful exploitation could still enable data theft or further system compromise.

  • CVE-2026-12466HIGH 8.8

    A memory safety flaw in Chrome's WebRTC component allows attackers to run malicious code on Windows machines. An attacker can craft a deceptive webpage that, when visited by an unaware user, exploits the heap buffer overflow to gain control of the browser process. This is a remote attack requiring only that a user click or visit a malicious link—no special permissions or prior system compromise needed.

  • CVE-2026-13835HIGH 8.8

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to corrupt the browser's memory heap. This type of corruption can lead to complete compromise of the affected system—including theft of sensitive data, installation of malware, or loss of system control. The vulnerability requires user interaction (visiting a malicious site) but is otherwise straightforward to exploit.

  • CVE-2026-13884HIGH 8.8

    CVE-2026-13884 is an integer overflow vulnerability in the Chromecast component of Google Chrome. A local attacker on the same network can send malicious network traffic to trigger the overflow and achieve arbitrary code execution with no user interaction required. This is a serious local network attack, not an internet-facing threat.

  • CVE-2026-14385HIGH 8.8

    A heap buffer overflow vulnerability exists in the ANGLE graphics rendering component within Google Chrome on macOS. An attacker can exploit this by hosting a malicious HTML page—when a user visits the page, Chrome's rendering engine writes data beyond allocated memory boundaries, potentially compromising the confidentiality, integrity, and availability of the browser process. This is a remote attack requiring no special privileges, though it does require user interaction (visiting a crafted page).

  • CVE-2026-14415HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows heap memory corruption when a user interacts with a malicious webpage through specific UI gestures. An attacker crafts an HTML page that, when visited and engaged with in particular ways, corrupts the heap—a critical memory region—potentially leading to code execution or application crash. Chrome versions before 150.0.7871.46 are vulnerable. The attack requires user interaction, not silent exploitation.

  • CVE-2026-15123HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser handles the Document Object Model (DOM) that could allow attackers to corrupt memory on your system. An attacker could craft a malicious web page that, when visited, exploits this vulnerability to gain control over sensitive data, modify web content, or crash your browser. The vulnerability requires user interaction—you must visit the malicious page—but no special user privileges are needed, and the attacker doesn't need network access beyond hosting the page.

  • CVE-2026-44420HIGH 8.8

    FreeRDP, a widely-used open-source Remote Desktop Protocol implementation, contains a flaw in its clipboard handling that allows an authenticated attacker to crash the RDP server or potentially execute arbitrary code. A malicious RDP client can send a specially crafted clipboard message with an invalid size parameter, causing the server to write past the bounds of allocated memory. This affects FreeRDP versions prior to 3.26.0. The vulnerability requires valid RDP credentials to exploit, limiting the attack surface to authenticated threat actors.

  • CVE-2026-44421HIGH 8.8

    FreeRDP, an open-source Remote Desktop Protocol client, contains a memory safety flaw that can be exploited by a malicious RDP server. When a FreeRDP client connects to an attacker-controlled server with graphics acceleration enabled, the attacker can send specially crafted network packets that trigger a heap buffer overflow during graphics operations. This memory corruption can crash the client or potentially allow remote code execution on the user's machine. The vulnerability requires user interaction (initiating an RDP connection) but does not require authentication, making it a practical attack vector against organizations that rely on remote desktop functionality.

  • CVE-2026-47289HIGH 8.8

    A heap-based buffer overflow vulnerability exists in Remote Desktop Client that could allow an attacker to run malicious code on a user's computer over the network. The flaw requires user interaction (such as connecting to a malicious RDP server or opening a crafted file) but does not require any authentication. If exploited, an attacker could gain full control of the affected system.

  • CVE-2026-52720HIGH 8.8

    GStreamer's RFB (VNC client) library contains a heap buffer overflow flaw in how it validates incoming rectangle dimensions from a VNC server. Instead of checking each dimension separately, the code only verifies the total area, allowing an attacker-controlled server to send a rectangle that overflows the framebuffer memory. A user tricked into connecting to a malicious VNC server could experience a crash or, more seriously, arbitrary code execution on their system.

  • CVE-2026-56645HIGH 8.8

    Microsoft Edge (Chromium-based) contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code remotely. The vulnerability requires user interaction—such as visiting a malicious webpage or opening a crafted document—but does not require authentication. Once triggered, an attacker gains the same privileges as the user running the browser, potentially enabling credential theft, malware installation, or lateral movement within a network.

  • CVE-2026-9939HIGH 8.8

    A heap buffer overflow vulnerability in Chrome's WebCodecs component allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux platforms. Because it requires user interaction (clicking a link or visiting a site) but can bypass Chrome's sandbox protections, it represents a significant remote code execution risk for Chrome users.

  • CVE-2026-9940HIGH 8.8

    A heap buffer overflow vulnerability exists in the ANGLE graphics library used by Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious HTML page that, when visited by a user, corrupts heap memory in the browser process. This memory corruption could allow the attacker to execute arbitrary code or crash the browser. The vulnerability requires user interaction (visiting a malicious website) but does not require any special privileges or complex attack setup.

  • CVE-2026-55999HIGH 8.5

    A heap buffer overflow vulnerability exists in X.Org's X server and XWayland that allows local attackers with X connection access to crash the server or potentially execute code by providing specially crafted PCX font files. The flaw stems from insufficient validation of glyph boundaries during font handling, enabling memory corruption when the SetFont operation processes malicious font data.

  • CVE-2026-56001HIGH 8.5

    A heap buffer overflow exists in libXfont2, a font rendering library used by X Server. The vulnerability occurs when the BitmapScaleBitmaps function processes specially crafted font data with oversized 32-bit values that exceed buffer boundaries. An authenticated attacker who can communicate with the X Server could exploit this flaw to execute arbitrary code with X Server privileges. The vulnerability affects libXfont2 versions prior to 2.0.8.

  • CVE-2026-56002HIGH 8.5

    A memory corruption flaw in libXfont2 allows authenticated X clients to crash the X server or execute arbitrary code within it. The vulnerability exists in the font file parsing function pcfReadFont(), which fails to validate glyph boundary data before writing to heap memory. An attacker with valid X client credentials can trigger this condition by supplying a malformed font file, potentially compromising the entire X display session and any services relying on it.

  • CVE-2026-56003HIGH 8.5

    A heap buffer overflow exists in libXfont2, the font library used by X servers. When processing specially crafted PCF (Portable Compiled Font) files, the ComputeScaledProperties() function fails to validate buffer sizes properly, allowing an authenticated X client to trigger memory corruption and execute arbitrary code with X server privileges. The vulnerability requires an authenticated connection to an X server and careful exploitation, but succeeds regardless of memory protections on vulnerable systems.

  • CVE-2026-47635HIGH 8.4

    A heap-based buffer overflow vulnerability exists in Microsoft Office 2024 that allows an attacker with local access to execute arbitrary code with the privileges of the user running Office. The vulnerability requires no user interaction or special privileges to trigger, making it a direct local code execution risk for anyone with system access to an affected machine.

  • CVE-2026-10929HIGH 8.3

    A memory safety flaw in ANGLE (the graphics abstraction layer used by Chrome) allows an attacker who has already compromised Chrome's sandboxed renderer process to escape that sandbox and gain full system access on Android devices. The attacker must trick a user into visiting a malicious webpage. This affects Chrome versions prior to 149.0.7827.53 on Android.

  • CVE-2026-10949HIGH 8.3

    A heap buffer overflow vulnerability in Google Chrome's video handling component allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the overflow, but exploitation requires the renderer to be already compromised—making this a post-compromise escape vector rather than a direct attack from an untrusted webpage. Chrome versions before 149.0.7827.53 are vulnerable on Windows, macOS, and Linux systems.

  • CVE-2026-12010HIGH 8.3

    A heap buffer overflow vulnerability exists in the GPU rendering component of Google Chrome on Android versions before 149.0.7827.115. The vulnerability requires an attacker to first compromise the browser's renderer process and then serve a specially crafted web page to trigger the overflow. If successfully exploited, the attacker could potentially break out of Chrome's sandbox and gain broader system access. This is a high-severity issue with a CVSS score of 8.3.

  • CVE-2026-12030HIGH 8.3

    A memory safety flaw in Google Chrome's GPU rendering engine on Android allows a remote attacker to escape the browser sandbox if they first compromise the renderer process. An attacker would need to trick a user into visiting a malicious webpage after achieving initial renderer compromise, potentially leading to full device compromise. This is a high-severity issue because it bridges from the already-isolated renderer to the broader Android system.

  • CVE-2026-14427HIGH 8.3

    A memory corruption bug exists in Google Chrome's Skia graphics library that could allow an attacker to break out of Chrome's sandbox protection. The vulnerability requires an attacker to first compromise Chrome's renderer process—the component that displays web pages—and then serve a specially crafted HTML page to trigger a heap buffer overflow. If successfully exploited, the attacker could potentially escape the sandbox and gain broader access to the system.

  • CVE-2026-9915HIGH 8.3

    A heap buffer overflow vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome, affecting versions prior to 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to potentially escape the browser sandbox and gain elevated privileges on the system. This requires the attacker to first compromise the renderer, making it a post-compromise threat rather than a direct entry point.

  • CVE-2026-9924HIGH 8.3

    A flaw in the ANGLE graphics library (which Chrome uses to render graphics on Windows) can cause memory corruption when processing specially crafted web content. An attacker who has already compromised Chrome's sandboxed renderer process could exploit this to escape the sandbox and gain full system access. The vulnerability requires user interaction—the victim must open a malicious webpage—but once the renderer is compromised, the attacker has a path to execute code outside the sandbox.

  • CVE-2026-9926HIGH 8.3

    A memory error in Chrome's graphics processing component (ANGLE) could allow an attacker who has already compromised the renderer process to break out of the sandbox and access the wider system. The vulnerability requires the attacker to deliver a specially crafted webpage and the user to interact with it, but once triggered, it could lead to full system compromise. The issue affects Chrome versions prior to 148.0.7778.216.

  • CVE-2026-47652HIGH 8.2

    A memory defect in Windows Hyper-V can allow someone with high-level system access to run malicious code on an affected machine. The flaw resides in how the hypervisor manages heap memory, leaving a window for buffer overflow attacks that bypass normal protections. This is a serious but constrained threat: exploitation requires administrative or hypervisor-level credentials, meaning it's not a remote vulnerability and the attacker must already have substantial control of the system.

  • CVE-2026-2467HIGH 8.1

    A heap-based buffer overflow vulnerability exists in RTI Connext Professional's core libraries that allows authenticated users to overflow variables and tags in memory. An attacker with valid credentials can trigger this flaw to corrupt data or crash the application, but cannot directly read sensitive information. The vulnerability affects multiple versions of Connext Professional spanning several major releases.

  • CVE-2026-42055HIGH 8.1

    NGINX Plus and NGINX Open Source contain a heap buffer overflow vulnerability in their HTTP/2 and gRPC proxy modules. When specific configuration conditions are met—proxy_http_version set to 2 or grpc_pass enabled, ignore_invalid_headers turned off, and large_client_header_buffers exceeding 2MB—an attacker can craft oversized headers to trigger a buffer overflow. This can crash the NGINX worker process or, under certain circumstances (particularly when ASLR is disabled), lead to remote code execution. The vulnerability requires specific configuration and network conditions but poses significant risk to affected deployments.

  • CVE-2026-56123HIGH 8.1

    socat, a utility for establishing two-way network data streams, has a critical flaw in how it parses SOCKS5 proxy responses. When connecting through a malicious SOCKS5 proxy, an attacker can craft a specially formed response that causes socat to write arbitrary data into its own memory beyond the intended boundaries. This memory corruption could allow the attacker to crash the application or potentially execute code on the affected system. The vulnerability affects socat versions 1.8.0.0 through 1.8.1.1.

  • CVE-2026-0059HIGH 8.0

    A heap buffer overflow vulnerability in Android's SDP (Session Description Protocol) discovery module allows an attacker on the same network segment to execute code with the privileges of the affected process. No user action is required, and the attacker needs only basic network access—the flaw can be triggered remotely through specially crafted SDP packets. This is a serious local/adjacent network attack vector that bypasses normal authentication and user interaction requirements.

  • CVE-2026-20452HIGH 8.0

    A heap buffer overflow vulnerability exists in MediaTek's wireless LAN access point driver that allows a nearby attacker with local user privileges to corrupt memory and achieve remote code execution. The flaw requires the attacker to be on the same local network segment but does not require any user interaction to trigger. Exploitation would grant the attacker the same privilege level as the user running the affected driver—typically limited, but sufficient to compromise the integrity and confidentiality of the device.

  • CVE-2026-0100HIGH 7.8

    A heap buffer overflow vulnerability exists in Android's resource loading code (LoadedArsc.cpp) that allows a local attacker with standard user privileges to write data beyond the intended buffer boundaries. This memory corruption can be exploited to gain elevated system privileges without requiring special permissions or user interaction, making it a serious local privilege escalation vector.

  • CVE-2026-11822HIGH 7.8

    SQLite versions prior to 3.53.2 contain memory safety flaws in the FTS5 full-text search module. When a user opens a specially crafted database file and runs a full-text search query, the vulnerability can trigger memory corruption that crashes the application, exhausts available memory, or potentially allows code execution. The vulnerability requires user interaction—a victim must open the malicious database—but once triggered, the impact is severe.

  • CVE-2026-11824HIGH 7.8

    SQLite versions before 3.53.2 contain a critical flaw in their full-text search capability that can be exploited by opening a specially crafted database file. When an application uses the FTS5 feature and processes search queries against the malicious database, attackers can trigger a memory corruption issue that crashes the application or potentially executes code with the privileges of the user running SQLite. The vulnerability requires local access and user interaction (opening a file), but poses significant risk to applications that accept untrusted database files.

  • CVE-2026-12193HIGH 7.8

    VS Revo RevoUninstaller versions 2.5.x and 2.6.x contain a heap-based buffer overflow flaw in the RevoDetector.sys driver's IOCTL handler. A local attacker with standard user privileges can exploit this to crash the system or potentially execute code with elevated privileges. The vulnerability requires local access and cannot be exploited remotely. A public exploit exists, elevating the practical risk. Upgrading to version 2.7.0 eliminates the vulnerability.

  • CVE-2026-2049HIGH 7.8

    GIMP contains a heap buffer overflow vulnerability in its HDR file parser that can lead to remote code execution. When a user opens a malicious HDR file or is tricked into visiting a compromised page hosting one, an attacker can overflow a memory buffer and execute arbitrary code with the privileges of the user running GIMP. The vulnerability requires user interaction but poses significant risk to creative professionals and any organization using GIMP for image processing workflows.

  • CVE-2026-2050HIGH 7.8

    GIMP, the widely-used open-source image editor, contains a vulnerability in how it processes HDR (High Dynamic Range) image files. When a user opens a specially crafted malicious HDR file, an attacker can exploit improper input validation to overflow a memory buffer and execute arbitrary code on the affected system. This is a local attack that requires user interaction—an attacker cannot exploit it remotely without social engineering a user to open a malicious file.

  • CVE-2026-34698HIGH 7.8

    Adobe InDesign Desktop contains a memory handling flaw that allows attackers to execute arbitrary code on a user's computer if the user opens a specially crafted file. The vulnerability affects InDesign versions 21.3, 20.5.3 and earlier on both Windows and macOS systems. While the flaw is serious, exploiting it requires social engineering or file delivery—an attacker cannot trigger it remotely over the network.

  • CVE-2026-34699HIGH 7.8

    Adobe InDesign Desktop contains a heap memory vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. The flaw exists in versions 21.3, 20.5.3, and earlier on both Windows and macOS. An attacker would need to trick a user into opening a specially crafted file—such as an InDesign document—to trigger the vulnerability. If successful, the attacker gains the same permissions as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.

  • CVE-2026-34701HIGH 7.8

    Adobe InDesign Desktop has a memory safety flaw that allows attackers to execute arbitrary code on a victim's machine by crafting a malicious document. When an unsuspecting user opens the file in InDesign 21.3, 20.5.3, or earlier versions, the vulnerability is triggered, giving the attacker the same privileges as the user running InDesign. This is a serious risk for design teams and publishers who regularly work with untrusted or externally-sourced documents.

  • CVE-2026-34707HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a memory safety flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability is triggered when a user opens a specially crafted malicious file, making it a file-based attack vector that relies on social engineering or document distribution. The flaw exists in how InCopy handles memory allocation during file parsing, creating conditions where an attacker-controlled payload can overwrite adjacent heap memory and gain code execution privileges.

  • CVE-2026-40404HIGH 7.8

    A flaw in Windows' Universal Disk Format (UDF) file system driver allows a logged-in user to gain elevated privileges on their machine. An attacker with basic user access can exploit a memory corruption issue in the UDFS driver to execute code with system-level permissions, potentially taking full control of the affected computer. This is a local-only vulnerability—attackers cannot exploit it remotely—but it represents a significant post-compromise escalation path and a serious risk in multi-tenant or shared-access environments.

  • CVE-2026-42980HIGH 7.8

    CVE-2026-42980 is a privilege escalation flaw in the Windows NT kernel that allows a user with local access to gain full administrative control of an affected system. The vulnerability stems from an integer underflow condition in memory management code. An attacker who has already logged into the machine can exploit this weakness to run code with the highest privileges, potentially compromising the entire system. This is a serious risk in environments where users share systems or where insider threats are a concern.

  • CVE-2026-44808HIGH 7.8

    A memory corruption flaw in Windows Desktop Window Manager (DWM) Core Library allows a user with local system access to escalate their privileges to a higher level of system access. The vulnerability stems from improper handling of memory buffers and requires an authenticated user to trigger, but does not require user interaction once triggered. This is a local privilege escalation vector that could allow an attacker with initial system access to gain administrative control.

  • CVE-2026-44811HIGH 7.8

    A heap-based buffer overflow exists in Windows DWM (Desktop Window Manager) Core Library that allows a user already logged into a Windows 11 system to elevate their privileges to a higher level of access. An attacker with an existing local account would need to craft specific input or manipulate the DWM process to trigger the memory corruption, potentially gaining system-level permissions. This is a local-only vulnerability and does not enable remote compromise.

  • CVE-2026-44819HIGH 7.8

    A heap-based buffer overflow vulnerability exists in Microsoft Office that allows an attacker to execute arbitrary code on a victim's system. The attack requires local access and user interaction—specifically, the user must open a specially crafted Office document. Once triggered, the vulnerability grants the attacker the same permissions as the logged-in user, potentially compromising sensitive data, modifying files, or installing malware. This is a significant local privilege escalation and code execution risk affecting multiple Office versions and SharePoint Server.

  • CVE-2026-44824HIGH 7.8

    A heap-based buffer overflow vulnerability exists in Microsoft Office that allows an attacker to run malicious code on a user's computer. The vulnerability requires user interaction—such as opening a specially crafted document—but does not require the attacker to be logged in or have elevated permissions. Successful exploitation can lead to complete compromise of the affected system, including theft of sensitive data and installation of malware.

  • CVE-2026-45469HIGH 7.8

    Microsoft Office Excel contains an integer underflow vulnerability that allows a local attacker to execute arbitrary code on a victim's machine. The flaw resides in how Excel processes certain numeric values internally, causing memory management errors. An attacker must convince a user to open a specially crafted spreadsheet file to trigger the vulnerability. Once code execution is achieved, the attacker gains the same privileges as the user running Excel, potentially enabling data theft, malware installation, or lateral movement within the organization.

  • CVE-2026-45475HIGH 7.8

    Microsoft Office contains a heap-based buffer overflow vulnerability that allows an attacker with local access to execute arbitrary code with the privileges of the user running Office. The flaw requires user interaction—such as opening a malicious document—but once triggered, provides complete control over the affected system. This is a serious local privilege escalation risk for organizations relying on Microsoft Office across their workforce.

  • CVE-2026-45636HIGH 7.8

    A heap-based buffer overflow vulnerability exists in Windows NTFS that allows an attacker with local access to execute arbitrary code on affected systems. The vulnerability requires user interaction—such as opening a specially crafted file—but does not require elevated privileges to trigger. Once exploited, an attacker can achieve full system compromise including reading sensitive data, modifying files, and disrupting system availability.

  • CVE-2026-45638HIGH 7.8

    A memory corruption flaw in Windows' Ancillary Function Driver for WinSock can allow an attacker with local system access to bypass privilege controls and gain full administrative rights. The vulnerability exists in how the driver handles network socket operations and does not require user interaction to exploit. An attacker would need to already have a foothold on the machine, but once they do, this bug becomes a direct path to system-level control.

  • CVE-2026-47747HIGH 7.8

    stable-diffusion.cpp, a C/C++ library for running inference on diffusion models like Stable Diffusion and Flux, contains a memory safety flaw in its checkpoint file parser. When processing .ckpt model files, a sign-confusion bug in the BINUNICODE opcode handler causes the parser to interpret a negative length value as an extremely large positive number, triggering an out-of-bounds memory copy that corrupts the heap. An attacker who controls a .ckpt file can exploit this to crash applications or potentially execute arbitrary code. The vulnerability affects versions prior to master-584-0a7ae07.

  • CVE-2026-47749HIGH 7.8

    A flaw in stable-diffusion.cpp allows an attacker to corrupt the memory of applications that load malicious model checkpoint files (.ckpt format). The vulnerability exists in how the library parses PyTorch checkpoint files—specifically in the SHORT_BINUNICODE opcode handler. An improperly crafted .ckpt file can exploit a sign-handling bug to trigger an oversized memory copy operation, immediately corrupting the application's heap. If you use stable-diffusion.cpp to load model files from untrusted sources (like public model repositories), a crafted file could crash your application or potentially enable code execution. The risk is local and requires user interaction to load a malicious file.

  • CVE-2026-47952HIGH 7.8

    Adobe Acrobat Reader contains a memory safety flaw that allows attackers to execute arbitrary code on a victim's computer when a malicious PDF or related document is opened. The vulnerability affects multiple versions across Windows and macOS platforms. While exploitation requires a user to be tricked into opening a specially crafted file, the impact is severe—an attacker could gain complete control of the user's system, steal data, or install malware. This is a classic code execution risk in a ubiquitous document viewer, making it a meaningful concern for any organization with Acrobat users.

  • CVE-2026-47964HIGH 7.8

    Adobe's DNG SDK (Digital Negative Software Development Kit), a widely used library for processing raw image files, contains a heap-based buffer overflow flaw in versions 1.7.1 2536 and earlier. An attacker can craft a malicious DNG image file that, when opened by a user, triggers the overflow and executes arbitrary code with the privileges of the person viewing the file. No special access or authentication is required; the only barrier is social engineering to get a victim to open the file.

  • CVE-2026-48291HIGH 7.8

    A heap-based buffer overflow vulnerability in Adobe Format Plugins version 1.1.2 and earlier allows attackers to execute arbitrary code on an affected system. The vulnerability requires a user to open a specially crafted malicious file, making it a user-interaction-dependent attack. Once exploited, an attacker gains the same privileges as the user running the application, potentially compromising sensitive data or system integrity.

  • CVE-2026-48292HIGH 7.8

    Format Plugins, an Adobe product, contains a memory handling flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability exists in versions 1.1.2 and earlier. An attacker must trick a user into opening a specially crafted file to trigger the vulnerability—there is no remote attack vector. Once exploited, the attacker gains the same privileges as the logged-in user, potentially leading to data theft, system compromise, or lateral movement within the network.

  • CVE-2026-48574HIGH 7.8

    A heap-based buffer overflow flaw in Windows Media could allow an attacker with local access to execute arbitrary code on a vulnerable system. The vulnerability requires user interaction (such as opening a malicious media file) but does not need elevated privileges to trigger. Successful exploitation grants the attacker the same privileges as the logged-in user, potentially leading to full system compromise if that user has administrative rights.

  • CVE-2026-56208HIGH 7.6

    A heap buffer overflow has been discovered in libaom, the reference implementation of the AV1 video codec. When the encoder's Look-Ahead Processing mode is enabled with certain frame lag settings, it incorrectly writes 232 bytes of data beyond the intended buffer boundary on every frame after the second. This corruption can crash the encoder process or, in worst-case scenarios, enable an attacker to execute arbitrary code. The vulnerability is reachable if an attacker can control encoder settings—a realistic threat in transcoding services, WebRTC applications, or any system that accepts untrusted AV1 encoding parameters.

  • CVE-2023-43688HIGH 7.5

    Malwarebytes versions 4.x and 5.x contain a heap buffer overflow vulnerability in buffer encryption utilities. An unauthenticated attacker on the network can trigger this condition to crash the Malwarebytes service, causing a denial of service. The vulnerability does not allow data theft or system compromise—it targets availability. While network-accessible, the technical bar to exploit is moderate rather than trivial.

  • CVE-2026-10946HIGH 7.5

    Google Chrome versions before 149.0.7827.53 contain a heap buffer overflow vulnerability in its media processing component. An attacker can exploit this by hosting a specially crafted HTML page and convincing a user to interact with it in specific ways—such as clicking, dragging, or performing other UI gestures. If successful, the attacker gains the ability to run arbitrary code, but crucially, that code executes within Chrome's sandbox, limiting lateral damage to the user's system. The vulnerability requires active user involvement, which raises the bar for exploitation but remains a meaningful risk given how often users interact with web content.

  • CVE-2026-12844HIGH 7.5

    List::Util::XS, a Perl module used to optimize list processing operations, contains a critical memory safety flaw in its pairwise() function. When the function processes pairs of values, it allocates memory to store results but fails to allocate enough space if a single block invocation returns a large amount of data. Specifically, the memory allocation strategy grows by only four times the current size in one step, but if a block returns more than that, the function writes beyond the allocated buffer, corrupting heap memory. Any application using pairwise() with a block that can produce large outputs in a single call is at risk of denial of service or potential code execution.

  • CVE-2026-22164HIGH 7.5

    CVE-2026-22164 is a heap memory corruption vulnerability affecting GPU drivers or graphics subsystems. A non-privileged user can exploit improper GPU system call handling to corrupt kernel heap memory by creating specific resource types and supplying crafted parameters. While it requires local access to create and manipulate resources, successful exploitation could crash the system or potentially enable further attacks. The vulnerability is rated HIGH severity due to its availability impact.

  • CVE-2026-34355HIGH 7.5

    A buffer overflow vulnerability exists in Apache HTTP Server's mod_proxy_html module, affecting versions 2.4.67 and earlier. An attacker controlling an untrusted backend server can trigger this overflow, causing the Apache service to crash and become unavailable. The vulnerability requires network access but no authentication or user interaction to exploit.

  • CVE-2026-34356HIGH 7.5

    Apache HTTP Server contains a heap-based buffer overflow vulnerability affecting versions 2.4.0 through 2.4.67. The flaw can be triggered when the server is configured with ProxyPassReverse directives that process cookies, and communicates with a malicious backend server. An attacker controlling a backend server could exploit this to cause a denial of service by crashing the Apache process. While the vulnerability does not directly enable data theft or compromise, the crash impact is significant in production environments. Upgrade to version 2.4.68 or later to resolve the issue.

  • CVE-2026-42536HIGH 7.5

    A heap-based buffer overflow vulnerability exists in Apache HTTP Server versions 2.4.0 through 2.4.67 when processing XML content through the mod_xml2enc module. An attacker can send specially crafted XML data to trigger a memory corruption issue that causes the server to crash, resulting in denial of service. The vulnerability requires no authentication and can be exploited over the network without user interaction.

  • CVE-2026-42992HIGH 7.5

    A heap-based buffer overflow vulnerability exists in Microsoft Remote Desktop Client that could allow an attacker to execute malicious code on a user's machine over the network. The attack requires user interaction (such as connecting to a malicious RDP server) and involves complex conditions to exploit, but if successful would grant an attacker full control over the affected system. This is a serious flaw affecting multiple Windows versions and server platforms.

  • CVE-2026-42993HIGH 7.5

    A heap-based buffer overflow vulnerability exists in Microsoft's Remote Desktop Client that allows attackers to execute arbitrary code on affected systems over the network. The vulnerability requires user interaction (such as clicking a malicious file or accepting a connection) and success depends on system configuration, but once exploited grants full code execution with the privileges of the logged-in user. This affects multiple versions of Windows 10, Windows 11, and Windows Server 2022–2025.

  • CVE-2026-44799HIGH 7.5

    A heap-based buffer overflow vulnerability exists in Microsoft's Remote Desktop Client and related Windows components. An attacker can exploit this flaw remotely by sending specially crafted network traffic, potentially allowing them to execute arbitrary code with the privileges of the user running the vulnerable application. User interaction is required to trigger the vulnerability, such as opening a malicious remote desktop connection or accepting a prompt. This affects a wide range of Windows versions and Server editions.

  • CVE-2026-46520HIGH 7.5

    ImageMagick, a widely-used image editing library, contains a memory safety flaw that can crash or destabilize applications when processing multiple images of different sizes. The vulnerability exists in versions before 6.9.13-48 (legacy branch) and 7.1.2-23 (current branch). An attacker can trigger an out-of-bounds write by submitting specially crafted image files, leading to denial of service or potential code execution depending on system configuration and memory layout.

  • CVE-2026-51218HIGH 7.5

    A vulnerability in snap7 v1.4.3 allows attackers to crash systems by sending specially crafted network packets. The flaw is a heap buffer overflow in a core server function that handles data writes, meaning an attacker can overflow memory buffers to trigger a denial of service without needing authentication or user interaction. The vulnerability affects any system running the vulnerable snap7 library and exposed to network traffic.

  • CVE-2026-51219HIGH 7.5

    A heap memory overflow vulnerability exists in lib60870 versions 2.3.3 through 2.3.6 that can crash systems processing certain network messages. An unauthenticated attacker on the network can send a specially crafted payload to trigger the overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function, causing service interruption. No data theft or system compromise occurs; the primary impact is availability loss.

  • CVE-2026-3195HIGH 7.4

    CVE-2026-3195 is a heap memory corruption vulnerability in QEMU's virtual sound device. When the virtio-snd device processes incoming audio, a code path fails to validate whether incoming data fits within its buffer, enabling an attacker to write beyond allocated memory boundaries. The vulnerability stems from an incomplete fix to an earlier flaw (CVE-2024-7730). An attacker with local access to a QEMU guest or host with audio input enabled could exploit this to corrupt heap memory, potentially achieving code execution or denial of service.

  • CVE-2026-12912HIGH 7.3

    A vulnerability in libtiff, a widely-used image processing library, allows a local attacker to trigger a heap-based buffer overflow by opening a specially crafted TIFF image file with PixarLog compression. The flaw surfaces specifically when the decoder processes images using the 8-bit ABGR output format combined with a particular stride configuration. An attacker with local file access could potentially execute arbitrary code on the system or crash the application handling the image.

  • CVE-2026-24180HIGH 7.3

    NVIDIA DALI contains a heap-based buffer overflow vulnerability that allows a local attacker with limited privileges to cause memory corruption. An attacker with user-level access could exploit this by supplying crafted input—potentially through user interaction—to overflow a heap buffer and execute arbitrary code, modify data, crash the application, or leak sensitive information. This is a local-only attack that requires an existing foothold on the system.

  • CVE-2026-58379HIGH 7.3

    GIMP contains a memory corruption flaw in how it processes Paint Shop Pro (PSP) image files. When a user opens a specially crafted PSP file with low bit-depth image data, the application miscalculates how much memory to allocate, causing it to write data past the intended buffer boundary. An attacker can exploit this by distributing a malicious PSP file; if opened, it could allow the attacker to run arbitrary code on the victim's system or crash the application. The vulnerability requires user interaction—someone must be tricked into opening the file—but once that happens, the attacker gains significant control.

  • CVE-2026-45542HIGH 7.1

    A heap buffer overflow vulnerability exists in Espressif's IoT Development Framework (ESP-IDF) affecting the Security Scheme 2 (SRP6a) component used during initial device provisioning and session setup. When a device receives a provisioning request with a specially crafted username field, the security handler copies the user-supplied length into a smaller buffer than intended, corrupting heap memory and potentially causing the device to crash or behave unpredictably. An attacker within network range of the target device can trigger this without authentication.

  • CVE-2026-41108HIGH 7.0

    A memory safety flaw in Windows DNS could allow someone with local system access to break out of normal restrictions and gain full control of the computer. The vulnerability exists because DNS processes input in a way that can overflow a memory buffer, and an attacker positioned locally—such as a low-privilege user or service—could exploit this to run code with elevated permissions. This is not a remote vulnerability, but it poses a significant risk in multi-user or shared-system environments.

  • CVE-2026-45653HIGH 7.0

    A heap-based buffer overflow vulnerability in the Windows Kernel allows a user with local system access to overflow a memory buffer, enabling them to execute code with elevated privileges. The attack requires an authenticated user account and moderate technical effort to exploit, but if successful grants attacker control over the affected system. This is a local privilege escalation issue, not a remote attack vector.

  • CVE-2026-20462MEDIUM 6.7

    CVE-2026-20462 is a memory corruption vulnerability in Telephony that allows a privileged local attacker to escalate their System-level permissions further by exploiting a heap buffer overflow. No user interaction is required—the flaw can be triggered automatically by malicious code already running with System privileges. The vulnerability poses a risk in environments where system accounts or elevated processes may be compromised or where insider threats exist.

  • CVE-2026-48914MEDIUM 6.7

    QEMU, a widely-used virtualization platform, contains a flaw in its virtio-blk device that fails to properly validate the size of input descriptors. A malicious guest operating system—one with administrative privileges inside a virtual machine—can craft a specially formed SCSI request to trigger an out-of-bounds memory write on the host system. This could crash the QEMU process, disrupting all virtual machines running under that hypervisor. The attack requires the attacker to already have high-level access within the guest, so this is not a remote vulnerability from the untrusted internet.

  • CVE-2026-10993MEDIUM 6.5

    A heap buffer overflow vulnerability exists in Skia, the graphics rendering engine used by Google Chrome. By visiting a specially crafted webpage, an attacker can read sensitive data from Chrome's memory without requiring any special user permissions beyond clicking the link. The vulnerability affects Chrome versions before 149.0.7827.53 and has a CVSS severity rating of Medium.

  • CVE-2026-11143MEDIUM 6.5

    Google Chrome on Linux contains an out-of-bounds memory read vulnerability affecting versions prior to 149.0.7827.53. The flaw resides in Chrome's extension handling mechanism and allows a malicious extension—installed by a user—to read sensitive data directly from the browser's process memory. An attacker would need to trick a user into installing the malicious extension, but once installed, the extension can harvest information like passwords, session tokens, or other in-memory secrets without triggering additional user interaction.

  • CVE-2026-11884MEDIUM 6.5

    A flaw in 389 Directory Server allows an attacker with administrative privileges—or someone controlling a replication server—to crash the service by creating directory object definitions with unusually long inheritance fields. The underlying issue is that the server calculates buffer space without accounting for the full size of these fields, leading to memory corruption when data is written. This is a remnant of an earlier incomplete patch attempt.

  • CVE-2026-30040MEDIUM 6.5

    FastStone Image Viewer version 8.3 contains a memory overflow vulnerability in its core image processing engine (FSViewer.exe) that can be triggered when opening a specially crafted JPEG 2000 file. An attacker can exploit this by distributing a malicious JP2 file that, when opened by a user, causes the application to execute arbitrary code with the privileges of the person running FastStone. This is a remote attack requiring no special permissions or user interaction beyond opening the file.

  • CVE-2026-45696MEDIUM 6.5

    OpenEXR, the industry-standard image format for motion pictures, contains a flaw in its HTJ2K decoder that allows a maliciously crafted EXR file to crash any application that opens it. When processing the file, the decoder incorrectly trusts the declared image dimensions without validating them against the actual data buffer, causing it to read beyond allocated memory. Any tool that previews, validates, or processes EXR files—including thumbnail generators, asset management systems, and the exrcheck utility—is at risk. This affects versions 3.4.0 through 3.4.11.

  • CVE-2026-56789MEDIUM 6.5

    RTKLIB, a widely-used open-source library for GNSS positioning, contains a memory corruption flaw in how it parses satellite observation data from RINEX files. An attacker can craft a malicious RINEX file that declares an impossibly high number of satellites in a single epoch (more than the valid limit of 64) to trigger a heap buffer overflow. This can crash RTKLIB applications like rnx2rtkp and RTKPOST, potentially disrupting surveying, navigation, and geospatial workflows that depend on these tools.

  • CVE-2026-10194MEDIUM 6.3

    A heap-based buffer overflow exists in OFFIS DCMTK 3.7.0 within the query/retrieve service component (dcmqrscp). An authenticated attacker can trigger this flaw remotely by sending specially crafted requests to the image deletion function, potentially causing memory corruption, data loss, or service disruption. The vulnerability requires valid credentials to exploit but poses moderate risk in networked medical imaging environments where DCMTK is deployed.

  • CVE-2026-12805MEDIUM 6.3

    OFFIS DCMTK, a widely-used open-source DICOM toolkit for medical imaging, contains a buffer overflow vulnerability in its XML file parsing function. When the software processes a specially crafted XML file, an attacker can overwrite memory on the heap, potentially leading to information disclosure, data corruption, or application crash. The vulnerability requires user interaction—someone must open or process a malicious XML file—but no authentication is needed, and the attack can be triggered remotely by sending the file over the network.

  • CVE-2026-53465MEDIUM 6.2

    ImageMagick, a widely-used image editing and manipulation tool, contains a memory corruption vulnerability in versions before 7.1.2-25. When processing specially crafted multi-frame images using the SF3 encoder, the software can write data beyond allocated memory boundaries, potentially causing application crashes or system instability. This is a local vulnerability requiring no special privileges or user interaction to trigger.

  • CVE-2026-58306MEDIUM 6.1

    A heap-based buffer overflow has been identified in Samsung's open-source Escargot JavaScript engine. The vulnerability allows an attacker to overflow memory buffers during processing, potentially leading to application crashes or data corruption. Exploitation requires local access and user interaction, such as opening a malicious file or visiting a crafted webpage. The issue has been patched as of commit ef525f337fafddecde77a3c426212a84bb20cb98.