Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,564 CVEs tagged with CWE-122235 Critical, 1,767 High, 422 Medium, 140 Low, 0 Unrated.

CVE-2026-10229

Published Jun 1, 2026

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Thi…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-20452

Published Jun 1, 2026

In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10200

Published May 31, 2026

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manip…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-10194

Published May 31, 2026

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of th…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-44421

Published May 29, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending…

CVSS 8.8 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-44420

Published May 29, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboar…

CVSS 8.8 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-40528

Published May 29, 2026

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attack…

CVSS 1.0 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-9924

Published May 28, 2026

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandb…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9915

Published May 28, 2026

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48065

Published May 27, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-4391

Published May 27, 2026

A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2025-70103

Published May 27, 2026

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

CVSS 7.3 · High

CVE-2026-38427

Published May 27, 2026

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-9605

Published May 27, 2026

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes h…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-44983

Published May 26, 2026

smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an unde…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48689

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (ap…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-48691

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() fu…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-48690

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() fun…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-40033

Published May 26, 2026

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs…

CVSS 8.7 · High
evidence mentions
9
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-9541

Published May 26, 2026

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a m…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
33.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 326-350 of 2,564 CVEsPage 14 of 103