Skip to main content

CWE archive

CWE-118 CVEs

Programmatic archive

25 CVEs tagged with CWE-1188 Critical, 8 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-50367

Published Jul 14, 2026

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-54628

Published Aug 6, 2025

Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48902

Published Jun 6, 2025

Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37923

Published Jan 8, 2024

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37922

Published Jan 8, 2024

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37921

Published Jan 8, 2024

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0201

Published Apr 22, 2023

NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code executio…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36402

Published Sep 16, 2022

An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6130

Published Jan 11, 2019

Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2004

Published Mar 29, 2018

The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that imprope…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2003

Published Mar 29, 2018

The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2002

Published Mar 29, 2018

The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly pas…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2001

Published Mar 29, 2018

The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacke…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2000

Published Mar 29, 2018

The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-c…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-10872

Published Dec 22, 2017

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9411

Published Aug 18, 2017

In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-0302

Published May 9, 2017

In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5884

Published Feb 28, 2017

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1