Skip to main content

CWE archive

CWE-1285 CVEs

Programmatic archive

57 CVEs tagged with CWE-12854 Critical, 32 High, 19 Medium, 2 Low, 0 Unrated.

CVE-2026-12681

Published Jun 24, 2026

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes…

CVSS 8.9 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45352

Published May 29, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocat…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9100

Published May 20, 2026

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any appl…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44004

Published May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-43868

Published May 5, 2026

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0,…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2026-40886

Published Apr 23, 2026

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer'…

CVSS 7.7 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-33557

Published Apr 20, 2026

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.s…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
35.5
Vendor/product tagsBeta · best-effort

CVE-2018-25232

Published Mar 30, 2026

Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-32286

Published Mar 26, 2026

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing…

CVSS 7.5 · High
evidence mentions
23
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2026-32285

Published Mar 26, 2026

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of serv…

CVSS 7.5 · High
evidence mentions
20
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2019-25625

Published Mar 23, 2026

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Atta…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25622

Published Mar 23, 2026

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25593

Published Mar 22, 2026

jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Log directory con…

CVSS 6.8 · Medium

CVE-2025-2399

Published Mar 10, 2026

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Seri…

CVSS 5.9 · Medium

CVE-2026-2006

Published Feb 12, 2026

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to e…

CVSS 8.8 · High
evidence mentions
36
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2025-67268

Published Jan 2, 2026

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 12954…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
40.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-48511

Published Nov 24, 2025

Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48502

Published Nov 21, 2025

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55086

Published Oct 20, 2025

In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55087

Published Oct 17, 2025

In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8291

Published Oct 7, 2025

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, inste…

CVSS 4.3 · Medium
Showing 1-25 of 57 CVEsPage 1 of 3