Skip to main content

CWE archive

CWE-190 CVEs

Programmatic archive

3,302 CVEs tagged with CWE-190432 Critical, 1,919 High, 852 Medium, 97 Low, 2 Unrated.

CVE-2026-45130

Published May 8, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (…

CVSS 6.6 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-42199

Published May 8, 2026

Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s log…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-42217

Published May 7, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41142

Published May 7, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.…

CVSS 8.8 · High
evidence mentions
12
Buzz score
38.6
Vendor/product tagsBeta · best-effort

CVE-2026-43254

Published May 6, 2026

In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When processing TCP stream data in ovpn_tcp_recv, we receive la…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42144

Published May 4, 2026

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can b…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-7598

Published May 1, 2026

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the arg…

CVSS 6.9 · Medium
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2026-37540

Published May 1, 2026

OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit v…

CVSS 8.4 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-37537

Published May 1, 2026

collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-bounds write in Transport Protocol Data T…

CVSS 8.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-28532

Published Apr 30, 2026

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable…

CVSS 6.0 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-42798

Published Apr 30, 2026

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-37555

Published Apr 29, 2026

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line…

CVSS 7.5 · High
evidence mentions
21
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-41605

Published Apr 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes t…

CVSS 7.3 · High
evidence mentions
13
Buzz score
45.9
Vendor/product tagsBeta · best-effort

CVE-2026-41602

Published Apr 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended…

CVSS 7.5 · High
evidence mentions
16
Buzz score
47.8
Vendor/product tagsBeta · best-effort

CVE-2026-41416

Published Apr 24, 2026

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when proce…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33666

Published Apr 24, 2026

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the set…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33662

Published Apr 24, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.1…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-31649

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally co…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
39.9
Vendor/product tagsBeta · best-effort

CVE-2026-31648

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() When running stress-ng on my Arm64 mach…

CVSS 7.8 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-31641

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and tick…

CVSS 7.8 · High
evidence mentions
7
Buzz score
37.3
Vendor/product tagsBeta · best-effort

CVE-2026-31633

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response(), there's a potential integer…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32952

Published Apr 24, 2026

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds pani…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33471

Published Apr 22, 2026

nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` in…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-33611

Published Apr 22, 2026

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33596

Published Apr 22, 2026

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 226-250 of 3,302 CVEsPage 10 of 133