Skip to main content

CWE archive

CWE-839 CVEs

Programmatic archive

6 CVEs tagged with CWE-8391 Critical, 3 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2026-53176

Published Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_l…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-56968

Published Jun 23, 2026

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-48840

Published May 30, 2026

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2023-22854

Published Feb 13, 2023

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient res…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20925

Published Nov 24, 2020

An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1