Skip to main content

CWE archive

CWE-805 CVEs

Programmatic archive

54 CVEs tagged with CWE-8054 Critical, 34 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2026-53877

Published Jul 7, 2026

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-53016

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driv…

CVSS 7.8 · High
evidence mentions
14
Buzz score
47.1
Vendor/product tagsBeta · best-effort

CVE-2026-12549

Published Jun 22, 2026

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-1767

Published Jun 16, 2026

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer over…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-1766

Published Jun 16, 2026

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerab…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12087

Published Jun 15, 2026

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, s…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-44893

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a…

CVSS 7.5 · High
evidence mentions
13
Buzz score
39.4
Vendor/product tagsBeta · best-effort

CVE-2026-8091

Published May 7, 2026

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and…

CVSS 9.8 · Critical
evidence mentions
24
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-34002

Published May 5, 2026

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11…

CVSS 6.1 · Medium
evidence mentions
26
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2025-63547

Published May 1, 2026

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field

CVSS 7.5 · High

CVE-2026-31607

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT respo…

CVSS 9.8 · Critical
evidence mentions
19
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-41035

Published Apr 16, 2026

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka -…

CVSS 7.4 · High
evidence mentions
30
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-6245

Published Apr 15, 2026

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes rece…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-26955

Published Feb 25, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GD…

CVSS 8.8 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-20033

Published Feb 25, 2026

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affecte…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20010

Published Feb 25, 2026

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart,…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-1837

Published Feb 11, 2026

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is…

CVSS 8.7 · High
evidence mentions
5
Buzz score
40.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-0716

Published Jan 13, 2026

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset,…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-7048

Published Jan 6, 2026

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these…

CVSS 5.3 · Medium

CVE-2025-36463

Published Nov 17, 2025

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and De…

CVSS 7.3 · High

CVE-2025-36462

Published Nov 17, 2025

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and De…

CVSS 7.3 · High

CVE-2025-36461

Published Nov 17, 2025

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and De…

CVSS 7.3 · High

CVE-2025-36460

Published Nov 17, 2025

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and De…

CVSS 7.3 · High

CVE-2025-20360

Published Oct 15, 2025

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to r…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20315

Published Sep 24, 2025

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 54 CVEsPage 1 of 3