Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,555 CVEs tagged with CWE-122236 Critical, 1,757 High, 421 Medium, 137 Low, 4 Unrated.

CVE-2026-17951

Published Jul 30, 2026

Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium securit…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17935

Published Jul 30, 2026

Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secu…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17758

Published Jul 30, 2026

Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17680

Published Jul 30, 2026

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandb…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-13307

Published Jul 29, 2026

Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14266

Published Jul 29, 2026

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 7.0 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-67191

Published Jul 29, 2026

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-16463

Published Jul 29, 2026

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a c…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-48372

Published Jul 28, 2026

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-51275

Published Jul 28, 2026

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or cause…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-51274

Published Jul 28, 2026

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-51273

Published Jul 28, 2026

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The p…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-51271

Published Jul 28, 2026

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The function reads untrusted chunk si…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51269

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text in…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-51267

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension pat…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51266

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-contro…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51263

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51260

Published Jul 28, 2026

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code copies a full UINT16_MAX bytes wi…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51259

Published Jul 28, 2026

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent normal audio buffer rea…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-51235

Published Jul 27, 2026

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-55971

Published Jul 27, 2026

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, whic…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-66040

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap m…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66039

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplyin…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66036

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying…

CVSS 7.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66035

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in an…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4
Showing 1-25 of 2,555 CVEsPage 1 of 103