Skip to main content

CWE archive

CWE-190 CVEs

Programmatic archive

3,317 CVEs tagged with CWE-190437 Critical, 1,928 High, 854 Medium, 97 Low, 1 Unrated.

CVE-2026-64765

Published Jul 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvO…

CVSS 7.8 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-64694

Published Jul 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause u…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43818

Published Jul 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Pro…

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-43769

Published Jul 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvO…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
25.8

CVE-2026-43764

Published Jul 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause u…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-66758

Published Jul 27, 2026

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and heigh…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-66757

Published Jul 27, 2026

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and z…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-55969

Published Jul 27, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recom…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16554

Published Jul 27, 2026

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap arou…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-16280

Published Jul 24, 2026

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-66039

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplyin…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-13063

Published Jul 22, 2026

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. Mon…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53910

Published Jul 22, 2026

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
37.9

CVE-2026-16517

Published Jul 21, 2026

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is en…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
23.9

CVE-2026-16416

Published Jul 21, 2026

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium s…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47251

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it add…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-47714

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `w…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16408

Published Jul 21, 2026

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16395

Published Jul 21, 2026

Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16389

Published Jul 21, 2026

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,317 CVEsPage 1 of 133