CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-49746 | High | 7.1 v3 | 0.1% | - | -No fix available yet | 2026-08-07 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages. |
| CVE-2026-49745 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-07-24 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges. |
| CVE-2026-49744 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-07-24 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries. |
| CVE-2026-21734 | High | 7.7 v3 | 0.1% | - | -No fix available yet | 2026-06-26 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write. |
| CVE-2026-12290 | High | 8.1 v3 | 0.4% | - | Fix available | 2026-06-16 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
| CVE-2026-46244 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-06-05 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base header. This creates a desync between inner_thoff (wrong — points to extension header start) and l4proto (correct — e.g., IPPROTO_TCP), enabling transport header forgery and potential firewall bypass. This issue affects stable versions from Linux 6.2. For comparison, the normal (non-inner) IPv6 path correctly preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite ensures that ipv6_fi |
| CVE-2026-34193 | Medium | 4.3 v3 | 0.1% | - | -No fix available yet | 2026-06-01 | Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory. |
| CVE-2026-28764 | High | 7.8 v3 | 0.2% | - | -No fix available yet | 2026-05-21 | MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability |
| CVE-2026-42946 | High | 6.5 v3 | 0.9% | - | Fix available | 2026-05-16 | A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2026-41907 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-04-27 | uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0. |
| CVE-2025-33215 | Medium | 6.8 v3 | 0.3% | - | -No fix available yet | 2026-03-24 | NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of storage to other VMs. |
| CVE-2026-4693 | High | 7.5 v3 | 0.7% | - | Fix available | 2026-03-24 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. |
| CVE-2026-21732 | Critical | 9.6 v3 | 0.3% | - | -No fix available yet | 2026-03-20 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very large value in switch statements in GPU shader code can cause a segmentation fault in the GPU shader compiler due to an out-of-bounds write access. |
| CVE-2026-32829 | High | 7.5 v3 | 0.6% | - | Fix available | 2026-03-20 | lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 "match copy operations," allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is disabled) are affected, while all frame APIs are unaffected. The impact is potential exposure of sensitive data and secrets through crafted or malformed LZ4 input. This issue has been fixed in versions 0.11.6 and 0.12.1. |
| CVE-2026-20022 | Medium | 6.1 v3 | 0.2% | - | -No fix available yet | 2026-03-04 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon. This vulnerability is due to insufficient input validation when processing OSPF LSU packets. An attacker could exploit this vulnerability by sending crafted unauthenticated OSPF packets. A successful exploit could allow the attacker to write to memory outside of the packet data, causing the device to reload, resulting in a DoS condition. |
| CVE-2025-54152 | Medium | 6.5 v3 | 0.4% | - | Fix available | 2026-02-11 | A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later |
| CVE-2026-23764 | Unscored | - | 0.1% | - | -No fix available yet | 2026-01-22 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers allocate non-paged pool and map it into user space, where a length value associated with the allocation is exposed and can be modified by an unprivileged local attacker. On subsequent IOCTL handling, the corrupted length is used directly as the IoAllocateMdl length argument without adequate integrity checks before building and mapping the MDL, which can |
| CVE-2026-21487 | Medium | 6.1 v3 | 0.2% | - | Fix available | 2026-01-06 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in version 2.3.1.2. |
| CVE-2017-20211 | Unscored | - | 0.7% | - | -No fix available yet | 2025-11-12 | UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file). |
| CVE-2025-11232 | High | 7.5 v3 | 0.4% | - | Fix available | 2025-10-29 | To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly. This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2. |
| CVE-2025-47349 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-10-09 | Memory corruption while processing an escape call. |
| CVE-2025-27059 | High | 8.8 v3 | 0.1% | - | -No fix available yet | 2025-10-09 | Memory corruption while performing SCM call. |
| CVE-2025-25180 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-07-14 | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. |
| CVE-2024-53017 | Medium | 6.6 v3 | 0.1% | - | -No fix available yet | 2025-06-03 | Memory corruption while handling test pattern generator IOCTL command. |
| CVE-2025-46806 | Unscored | - | 0.4% | - | Fix available | 2025-06-02 | A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4. |
| CVE-2024-47893 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2025-05-17 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory. |
| CVE-2024-45570 | Medium | 6.6 v3 | 0.1% | - | -No fix available yet | 2025-05-06 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. |
| CVE-2025-0467 | High | 8.2 v3 | 0.2% | - | -No fix available yet | 2025-04-18 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-45557 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-04-07 | Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation. |
| CVE-2024-43060 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-03-03 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
| CVE-2024-52939 | High | 7.8 v3 | 0.2% | - | -No fix available yet | 2025-02-22 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory. |
| CVE-2024-47896 | Low | 3.3 v3 | 0.2% | - | -No fix available yet | 2025-02-22 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-12577 | High | 7.3 v3 | 0.2% | - | -No fix available yet | 2025-02-22 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-49840 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-02-03 | Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. |
| CVE-2024-45573 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2025-02-03 | Memory corruption may occour while generating test pattern due to negative indexing of display ID. |
| CVE-2024-47900 | High | 7.8 v3 | 0.2% | - | -No fix available yet | 2025-01-31 | Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory. |
| CVE-2024-52938 | High | 7.8 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory. |
| CVE-2024-52937 | Medium | 6.7 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-52936 | Medium | 4.4 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-52935 | Medium | 4.1 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
| CVE-2024-47895 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
| CVE-2024-47894 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2025-01-13 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
| CVE-2024-33041 | Medium | 6.7 v3 | 0.1% | - | -No fix available yet | 2025-01-06 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |
| CVE-2024-33036 | Medium | 6.7 v3 | 0.1% | - | -No fix available yet | 2024-12-02 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. |
| CVE-2017-11076 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2024-11-26 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2024-42391 | Medium | 4.3 v3 | 0.3% | - | -No fix available yet | 2024-11-18 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42390 | Medium | 4.3 v3 | 0.3% | - | -No fix available yet | 2024-11-18 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42389 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2024-11-18 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42388 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2024-11-18 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42387 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2024-11-18 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
- HighCVSS 7.1 v3·EPSS 0.1%·No fix yet
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
Published 2026-08-07
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
Published 2026-07-24
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Published 2026-07-24
- HighCVSS 7.7 v3·EPSS 0.1%·No fix yet
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write.
Published 2026-06-26
- HighCVSS 8.1 v3·EPSS 0.4%·Fix available
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
Published 2026-06-16
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base header. This creates a desync between inner_thoff (wrong — points to extension header start) and l4proto (correct — e.g., IPPROTO_TCP), enabling transport header forgery and potential firewall bypass. This issue affects stable versions from Linux 6.2. For comparison, the normal (non-inner) IPv6 path correctly preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite ensures that ipv6_fi
Published 2026-06-05
- MediumCVSS 4.3 v3·EPSS 0.1%·No fix yet
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
Published 2026-06-01
- HighCVSS 7.8 v3·EPSS 0.2%·No fix yet
MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
Published 2026-05-21
- HighCVSS 6.5 v3·EPSS 0.9%·Fix available
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2026-05-16
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.
Published 2026-04-27
- MediumCVSS 6.8 v3·EPSS 0.3%·No fix yet
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of storage to other VMs.
Published 2026-03-24
- HighCVSS 7.5 v3·EPSS 0.7%·Fix available
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Published 2026-03-24
- CriticalCVSS 9.6 v3·EPSS 0.3%·No fix yet
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very large value in switch statements in GPU shader code can cause a segmentation fault in the GPU shader compiler due to an out-of-bounds write access.
Published 2026-03-20
- HighCVSS 7.5 v3·EPSS 0.6%·Fix available
lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 "match copy operations," allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is disabled) are affected, while all frame APIs are unaffected. The impact is potential exposure of sensitive data and secrets through crafted or malformed LZ4 input. This issue has been fixed in versions 0.11.6 and 0.12.1.
Published 2026-03-20
- MediumCVSS 6.1 v3·EPSS 0.2%·No fix yet
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon. This vulnerability is due to insufficient input validation when processing OSPF LSU packets. An attacker could exploit this vulnerability by sending crafted unauthenticated OSPF packets. A successful exploit could allow the attacker to write to memory outside of the packet data, causing the device to reload, resulting in a DoS condition.
Published 2026-03-04
- MediumCVSS 6.5 v3·EPSS 0.4%·Fix available
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Published 2026-02-11
- UnscoredCVSS -·EPSS 0.1%·No fix yet
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers allocate non-paged pool and map it into user space, where a length value associated with the allocation is exposed and can be modified by an unprivileged local attacker. On subsequent IOCTL handling, the corrupted length is used directly as the IoAllocateMdl length argument without adequate integrity checks before building and mapping the MDL, which can
Published 2026-01-22
- MediumCVSS 6.1 v3·EPSS 0.2%·Fix available
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Use of Out-of-range Pointer Offset and have Improper Input Validation in its CIccProfile::LoadTag function. This issue is fixed in version 2.3.1.2.
Published 2026-01-06
- UnscoredCVSS -·EPSS 0.7%·No fix yet
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file).
Published 2025-11-12
- HighCVSS 7.5 v3·EPSS 0.4%·Fix available
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly. This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.
Published 2025-10-29
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption while processing an escape call.
Published 2025-10-09
- HighCVSS 8.8 v3·EPSS 0.1%·No fix yet
Memory corruption while performing SCM call.
Published 2025-10-09
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
Published 2025-07-14
- MediumCVSS 6.6 v3·EPSS 0.1%·No fix yet
Memory corruption while handling test pattern generator IOCTL command.
Published 2025-06-03
- UnscoredCVSS -·EPSS 0.4%·Fix available
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.
Published 2025-06-02
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.
Published 2025-05-17
- MediumCVSS 6.6 v3·EPSS 0.1%·No fix yet
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Published 2025-05-06
- HighCVSS 8.2 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-04-18
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Published 2025-04-07
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Published 2025-03-03
- HighCVSS 7.8 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.
Published 2025-02-22
- CVSS 3.3 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-02-22
- HighCVSS 7.3 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-02-22
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
Published 2025-02-03
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
Published 2025-02-03
- HighCVSS 7.8 v3·EPSS 0.2%·No fix yet
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
Published 2025-01-31
- HighCVSS 7.8 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- MediumCVSS 6.7 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- MediumCVSS 4.4 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- MediumCVSS 4.1 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
Published 2025-01-13
- MediumCVSS 6.7 v3·EPSS 0.1%·No fix yet
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
Published 2025-01-06
- MediumCVSS 6.7 v3·EPSS 0.1%·No fix yet
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Published 2024-12-02
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
Published 2024-11-26
- MediumCVSS 4.3 v3·EPSS 0.3%·No fix yet
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Published 2024-11-18
- MediumCVSS 4.3 v3·EPSS 0.3%·No fix yet
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Published 2024-11-18
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Published 2024-11-18
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Published 2024-11-18
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Published 2024-11-18
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.