Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,527 CVEs tagged with CWE-122226 Critical, 1,745 High, 420 Medium, 136 Low, 0 Unrated.

CVE-2026-48065

Published May 27, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-4391

Published May 27, 2026

A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2025-70103

Published May 27, 2026

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

CVSS 7.3 · High

CVE-2026-38427

Published May 27, 2026

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-9605

Published May 27, 2026

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes h…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-44983

Published May 26, 2026

smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an unde…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48689

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (ap…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-48691

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() fu…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-48690

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() fun…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-40033

Published May 26, 2026

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs…

CVSS 8.7 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-9541

Published May 26, 2026

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a m…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
33.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-7310

Published May 26, 2026

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48135

Published May 26, 2026

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48131

Published May 26, 2026

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to termi…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-9502

Published May 25, 2026

A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipu…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
32.3

CVE-2026-9500

Published May 25, 2026

A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility.…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-9365

Published May 24, 2026

A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG Dissector. The man…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-9256

Published May 22, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct,…

CVSS 9.2 · Critical
evidence mentions
15
Buzz score
47.7
Vendor/product tagsBeta · best-effort

CVE-2026-8997

Published May 22, 2026

vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-45252

Published May 21, 2026

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a gi…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44050

Published May 21, 2026

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Showing 301-325 of 2,527 CVEsPage 13 of 102