Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,433 CVEs tagged with CWE-476119 Critical, 1,293 High, 3,808 Medium, 212 Low, 1 Unrated.

CVE-2026-48829

Published May 24, 2026

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/dige…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.9

CVE-2026-41069

Published May 22, 2026

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39835

Published May 22, 2026

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertCh…

CVSS 5.3 · Medium
evidence mentions
40
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-43496

Published May 21, 2026

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked When red qdisc has childre…

CVSS 5.5 · Medium
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort

CVE-2026-32738

Published May 19, 2026

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32134

Published May 19, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-colli…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-47308

Published May 19, 2026

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47307

Published May 19, 2026

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested inst…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25110

Published May 19, 2026

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-32849

Published May 18, 2026

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is de…

CVSS 5.7 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-8783

Published May 18, 2026

A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the file ngap/dispatcher.go. Such manip…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-8782

Published May 18, 2026

A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message Handler. This manipu…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-8781

Published May 18, 2026

A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation result…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-8723

Published May 17, 2026

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is sy…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-44638

Published May 14, 2026

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode…

CVSS 2.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43480

Published May 13, 2026

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
27.0
Vendor/product tagsBeta · best-effort

CVE-2026-42442

Published May 12, 2026

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerabili…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34662

Published May 12, 2026

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exp…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34350

Published May 12, 2026

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 251-275 of 5,433 CVEsPage 11 of 218