Skip to main content

CWE archive

CWE-170 CVEs

Programmatic archive

52 CVEs tagged with CWE-17011 Critical, 17 High, 17 Medium, 7 Low, 0 Unrated.

CVE-2026-44452

Published Jul 16, 2026

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-12386

Published Jul 5, 2026

Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from <=4.1.5…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-55738

Published Jun 17, 2026

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR he…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-5067

Published Jun 9, 2026

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header pa…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8721

Published May 17, 2026

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's d…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-34464

Published May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34462

Published May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, a…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34032

Published May 4, 2026

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to ver…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-40334

Published Apr 18, 2026

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (li…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-33948

Published Apr 14, 2026

jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-2239

Published Mar 26, 2026

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occ…

CVSS 2.8 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-32837

Published Mar 17, 2026

miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-23749

Published Feb 26, 2026

Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to improper null termination of a blockwise transfer path. blockwi…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
30.9

CVE-2026-27692

Published Feb 25, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccT…

CVSS 7.1 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-67733

Published Feb 23, 2026

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the…

CVSS 8.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-24852

Published Jan 28, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, a heap buffe…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-21488

Published Jan 6, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Ove…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-2026

Published Dec 31, 2025

The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s we…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67790

Published Dec 17, 2025

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66220

Published Dec 3, 2025

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may inc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62792

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is c…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61912

Published Oct 10, 2025

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a b…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31197

Published Sep 18, 2024

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 52 CVEsPage 1 of 3