Skip to main content

CWE archive

CWE-364 CVEs

Programmatic archive

19 CVEs tagged with CWE-3640 Critical, 11 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-53185

Published Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device…

CVSS 7.8 · High
evidence mentions
8
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2026-52910

Published Jun 19, 2026

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0]…

CVSS 7.8 · High
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-46090

Published May 27, 2026

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side…

CVSS 7.8 · High
evidence mentions
24
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-33565

Published May 19, 2026

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-27766

Published May 19, 2026

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-24792

Published May 19, 2026

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31474

Published Apr 22, 2026

In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() isotp_sendmsg() uses only cmpxchg() on so->tx.state…

CVSS 7.8 · High
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-34771

Published Apr 4, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that regi…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-4684

Published Mar 24, 2026

Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thund…

CVSS 7.5 · High
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-53092

Published Oct 16, 2025

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, St…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7589

Published Aug 12, 2024

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6409

Published Jul 8, 2024

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd…

CVSS 7.0 · High
evidence mentions
3
Buzz score
20.4

CVE-2023-5676

Published Nov 15, 2023

In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1