CVE & CISA-KEV Catalog

384,788 CVEs1,686 actively exploited (KEV)
Active:
  • CVSS 9.3 v4·EPSS 0.5%·No fix yet

    An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

    Published 2026-08-28

  • CVSS 6.9 v4·EPSS 0.1%·Fix available

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.

    Published 2026-08-20

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

    Published 2026-08-12

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

    Published 2026-08-06

  • CVSS 8.1 v3·EPSS 4.0%·Fix available

    libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

    Published 2026-07-03

  • CVSS 5.7 v3·EPSS 0.4%·Fix available

    Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

    Published 2026-05-27

  • CVSS 7.5 v3·EPSS 0.5%·Fix available

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() then trust this corrupted cap value and may create out-of-bounds slices, leading to UB. This behavior is observable in release builds (integer overflow wraps), whereas debug builds panic due to overflow checks. This issue has been patched in version 1.11.1.

    Published 2026-03-04

  • CVSS 5.8 v3·EPSS 0.1%·No fix yet

    Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-02-06

  • CVSS 8.8 v3·EPSS 0.7%·Fix available

    A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

    Published 2025-08-25

  • CVSS 8.8 v3·EPSS 0.9%·Fix available

    A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

    Published 2025-08-25

  • CVSS 8.8 v3·EPSS 0.9%·Fix available

    A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

    Published 2025-08-25

  • CVSS 8.8 v3·EPSS 0.7%·Fix available

    A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integer overflow can be made to occur which will cause a heap-based buffer to overflow when reading the palette from the image. These conditions can allow for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

    Published 2025-08-25

  • CVSS 8.8 v3·EPSS 0.9%·Fix available

    A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

    Published 2025-08-25

  • CVSS 8.6 v3·EPSS 0.6%·No fix yet

    A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. This vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could cause the system to reload, resulting in a denial of service (DoS) condition.

    Published 2025-08-14

  • CVSS 9.8 v3·EPSS 0.6%·No fix yet

    An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b.

    Published 2025-08-08

  • CVSS 7.5 v3·EPSS 0.5%·Fix available

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.

    Published 2025-08-06

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-08-06

  • CVSS -·EPSS 0.3%·Fix available

    llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in commit 26a48ad699d50b6268900062661bd22f3e792579.

    Published 2025-07-10

  • CVSS 7.0 v3·EPSS 3.9%·Fix available

    Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.

    Published 2025-07-07

  • CVSS 8.4 v3·EPSS 0.3%·Fix available

    A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Published 2025-06-02

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory corruption while transmitting packet mapping information with invalid header payload size.

    Published 2025-04-07

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-04-07

  • CVSS 2.8 v3·EPSS 0.2%·No fix yet

    Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-02-06

  • CVSS 7.3 v3·EPSS 0.1%·No fix yet

    Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-01-08

  • CVSS 3.3 v3·EPSS 0.2%·Fix available

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.

    Published 2025-01-06

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory corruption while processing voice packet with arbitrary data received from ADSP.

    Published 2024-11-04

  • CVSS 4.0 v3·EPSS 0.4%·Fix available

    The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

    Published 2024-07-02

  • CVSS 8.2 v3·EPSS 0.4%·No fix yet

    oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid (traditional + post-quantum) keys and signatures. Unchecked length values are later used for memory reads and writes; malformed input can lead to crashes or information leakage. Handling of plain/non-hybrid PQ key operation is not affected. This issue has been patched in in v0.6.1. All users are advised to upgrade. There are no workarounds for this issue.

    Published 2024-06-17

  • CVSS 9.8 v3·EPSS 1.1%·No fix yet

    Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

    Published 2024-05-01

  • CVSS 6.7 v3·EPSS 1.0%·Fix available

    In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

    Published 2024-04-03

  • CVSS 8.4 v3·EPSS 0.1%·No fix yet

    Memory corruption while allocating memory for graphics.

    Published 2024-04-01

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

    Published 2024-04-01

  • CVSS 8.4 v3·EPSS 0.4%·Fix available

    `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

    Published 2024-03-19

  • CVSS 7.5 v3·EPSS 1.0%·Fix available

    An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.

    Published 2024-02-21

  • CVSS 7.0 v3·EPSS 0.3%·Fix available

    EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

    Published 2024-01-09

  • CVSS 8.4 v3·EPSS 0.2%·No fix yet

    Memory corruption in HLOS while invoking IOCTL calls from user-space.

    Published 2023-12-05

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory corruption while using the UIM diag command to get the operators name.

    Published 2023-12-05

  • CVSS 8.2 v3·EPSS 0.1%·No fix yet

    Memory corruption while loading an ELF segment in TEE Kernel.

    Published 2023-12-05

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

    Published 2023-11-14

  • CVSS 8.2 v3·EPSS 1.4%·Fix available

    An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

    Published 2023-10-11

  • CVSS 6.7 v3·EPSS 0.1%·No fix yet

    Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.

    Published 2023-09-05

  • CVSS 6.7 v3·EPSS 0.1%·No fix yet

    Memory corruption in RIL while trying to send apdu packet.

    Published 2023-08-08

  • CVSS 7.0 v3·EPSS 41%·Fix available

    Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.

    Published 2023-07-13

  • CVSS 6.0 v3·EPSS 0.2%·Fix available

    Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable denial of service via local access.

    Published 2023-05-10

  • CVSS 5.9 v3·EPSS 0.1%·No fix yet

    Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

    Published 2023-04-13

  • CVSS 8.4 v3·EPSS 0.1%·No fix yet

    Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.

    Published 2023-04-13

  • CVSS 8.4 v3·EPSS 0.1%·No fix yet

    Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.

    Published 2023-03-10

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

    Published 2023-03-10

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.

    Published 2023-02-12

  • CVSS 9.8 v3·EPSS 1.0%·Fix available

    A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

    Published 2022-10-11

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.