Skip to main content

CWE archive

CWE-195 CVEs

Programmatic archive

21 CVEs tagged with CWE-1951 Critical, 12 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-55737

Published Jul 27, 2026

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary t…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-55991

Published Jul 22, 2026

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entir…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49840

Published Jun 9, 2026

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwa…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41682

Published May 8, 2026

pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion due to port truncation via atoi(…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-26981

Published Feb 24, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 an…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-67897

Published Dec 14, 2025

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a vi…

CVSS 5.3 · Medium

CVE-2025-65495

Published Nov 24, 2025

Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52566

Published Jun 24, 2025

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer implementation (llama_vo…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49847

Published Jun 17, 2025

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in llama.cpp’s vocabular…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30646

Published Apr 9, 2025

A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an una…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24792

Published Jan 29, 2025

Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in th…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-25388

Published Mar 27, 2024

drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3635

Published Jul 12, 2023

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZ…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-43663

Published Mar 20, 2023

An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a b…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2020-1913

Published Sep 9, 2020

An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6560

Published Mar 31, 2017

illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3045

Published Mar 22, 2012

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote att…

CVSS 8.8 · High
Showing 1-21 of 21 CVEsPage 1 of 1