Skip to main content

CWE archive

CWE-393 CVEs

Programmatic archive

10 CVEs tagged with CWE-3931 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-55958

Published Jun 25, 2026

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fa…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-53092

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix linked reg delta tracking when src_reg == dst_reg Consider the case of rX += rX where src_reg and ds…

CVSS 7.8 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-9058

Published May 25, 2026

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the spe…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2025-24531

Published Jan 16, 2026

In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing au…

CVSS 6.7 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2025-5987

Published Jul 7, 2025

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to li…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32414

Published Apr 8, 2025

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in x…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37897

Published Jul 18, 2023

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|fi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5401

Published Feb 27, 2020

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent le…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1