Skip to main content

CWE archive

CWE-680 CVEs

Programmatic archive

105 CVEs tagged with CWE-68013 Critical, 77 High, 12 Medium, 3 Low, 0 Unrated.

CVE-2026-55200

Published Jun 17, 2026

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. R…

CVSS 9.2 · Critical
evidence mentions
15
Buzz score
47.7
Vendor/product tagsBeta · best-effort

CVE-2026-8376

Published May 26, 2026

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c ch…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24928

Published Feb 6, 2026

Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25541

Published Feb 4, 2026

Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-53510

Published Aug 25, 2025

A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52930

Published Aug 25, 2025

A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially craf…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52456

Published Aug 25, 2025

A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation an in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46407

Published Aug 25, 2025

A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an inte…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32468

Published Aug 25, 2025

A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an intege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-20263

Published Aug 14, 2025

A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-54952

Published Aug 8, 2025

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or ot…

CVSS 9.8 · Critical

CVE-2025-54623

Published Aug 6, 2025

Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53630

Published Jul 10, 2025

llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write.…

CVSS 8.9 · High

CVE-2025-32023

Published Jul 7, 2025

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48877

Published Jun 2, 2025

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-58107

Published Apr 7, 2025

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-57956

Published Feb 6, 2025

Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56451

Published Jan 8, 2025

Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55626

Published Jan 6, 2025

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6381

Published Jul 2, 2024

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may resu…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37305

Published Jun 17, 2024

oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from libo…

CVSS 8.2 · High

CVE-2024-33078

Published May 1, 2024

Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 105 CVEsPage 1 of 5