Export limit exceeded: 401126 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 26649 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (26649 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102730 1 Eclipse 1 Threadx/levelx(nand Driver) 2026-09-30 N/A
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)
CVE-2026-92870 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 7.5 High
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
CVE-2026-85644 1 Perl 1 Xs::parse::infix 2026-09-30 7.5 High
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);
CVE-2026-95281 1 Google 2 Android, Chrome 2026-09-30 9.6 Critical
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-103432 1 Apcupsd 1 Apcupsd 2026-09-30 8.1 High
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
CVE-2026-47544 1 Nvidia 1 Virtual Gpu Manager 2026-09-30 7.8 High
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-47535 1 Nvidia 1 Virtual Gpu Manager 2026-09-30 7.8 High
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-47536 1 Nvidia 1 Virtual Gpu Manager 2026-09-30 7.8 High
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-69272 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 7.1 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
CVE-2026-80490 2026-09-30 N/A
Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV. When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process. Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl. This can be triggered when the haystack is a numeric value, for example, my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] ); $ac->matches( 211 ); This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.
CVE-2026-75895 1 Osmocom 1 Libsmpp34 2026-09-30 7.5 High
In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.
CVE-2026-100387 1 Pgpointcloud 1 Pointcloud 2026-09-30 8.1 High
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.
CVE-2026-69271 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-30 8 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
CVE-2026-68897 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-30 7 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-68892 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-30 7.8 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-68891 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 4.7 Medium
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-68890 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-30 7.8 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-68889 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 7.1 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
CVE-2025-50343 1 Matio Project 1 Matio 2026-09-30 9.8 Critical
An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption. NOTE: Multiple third-parties note that the available evidence does not demonstrate a vulnerability exploitable through an attacker-controlled input path.
CVE-2026-103242 1 Redhat 2 Enterprise Linux, Hummingbird 2026-09-30 7.1 High
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.