Skip to main content

CWE archive

CWE-789 CVEs

Programmatic archive

185 CVEs tagged with CWE-7894 Critical, 84 High, 90 Medium, 7 Low, 0 Unrated.

CVE-2026-54890

Published Jul 27, 2026

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation.…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-65315

Published Jul 21, 2026

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-47667

Published Jul 21, 2026

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an An…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59844

Published Jul 21, 2026

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memo…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-71395

Published Jul 18, 2026

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns.…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-44453

Published Jul 16, 2026

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain cond…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-55407

Published Jul 16, 2026

Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in buffa's protobuf decoder allo…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-58559

Published Jul 15, 2026

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-40378

Published Jul 14, 2026

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-59204

Published Jul 14, 2026

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of rec…

CVSS 8.7 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-55213

Published Jul 10, 2026

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-55782

Published Jul 10, 2026

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp al…

CVSS 2.4 · Low
evidence mentions
5
Buzz score
22.9

CVE-2026-55781

Published Jul 10, 2026

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates th…

CVSS 2.4 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-40006

Published Jul 10, 2026

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59938

Published Jul 8, 2026

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actua…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-15053

Published Jul 8, 2026

Tanium addressed a denial of service vulnerability in Tanium Server.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14454

Published Jul 8, 2026

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. Thi…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-55079

Published Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDat…

CVSS 4.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-55380

Published Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without call…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55379

Published Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensio…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54060

Published Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) witho…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54059

Published Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.fromby…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-14684

Published Jul 5, 2026

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/Abs…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-14683

Published Jul 4, 2026

A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-11946

Published Jul 2, 2026

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 185 CVEsPage 1 of 8