← Back to feed Search feed

CWE-787 Out-of-bounds Write vulnerabilities

160 CVEs — updated 2026-09-21 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-54333UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. PriCRITICAL9.837%ileNVD2026-09-14
CVE-2026-54334UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. PriCRITICAL9.837%ileNVD2026-09-14
CVE-2026-65414An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.CRITICAL9.861%ileNVD2026-09-14
CVE-2026-11928IBM Verify Identity Access is vulnerable to a buffer overflow attack.CRITICAL9.822%ileNVD2026-09-15
CVE-2026-19773libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabiliCRITICAL9.850%ileNVD2026-09-15
CVE-2026-89783In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(CRITICAL9.852%ileNVD2026-09-16
CVE-2026-89969In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving aCRITICAL9.852%ileNVD2026-09-16
CVE-2026-90048In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_createCRITICAL9.842%ileNVD2026-09-16
CVE-2026-54626SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. ICRITICAL9.844%ileNVD2026-09-17
CVE-2026-54627SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. ICRITICAL9.838%ileNVD2026-09-17
CVE-2026-84383libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF itemCRITICAL9.849%ileNVD2026-09-18
CVE-2025-1744Out-of-bounds Write in radare2CRITICAL9.842%ileMicrosoft2025-02-11
CVE-2026-93393A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platfCRITICAL9.221%ileNVD2026-09-17
CVE-2026-43790The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, CRITICAL9.151%ileNVD2026-09-14
CVE-2026-73194DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets theCRITICAL9.141%ileMicrosoft2026-08-11
CVE-2026-43815A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS SonomaHIGH8.838%ileNVD2026-09-14
CVE-2026-65374A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SeqHIGH8.833%ileNVD2026-09-14
CVE-2026-65391An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6HIGH8.833%ileNVD2026-09-14
CVE-2026-0159In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote codeHIGH8.820%ileNVD2026-09-15
CVE-2026-0170In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This cHIGH8.820%ileNVD2026-09-15
CVE-2026-0171In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remoHIGH8.821%ileNVD2026-09-15
CVE-2026-0200In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escaHIGH8.821%ileNVD2026-09-15
CVE-2026-55331In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead toHIGH8.820%ileNVD2026-09-15
CVE-2026-56920In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code.HIGH8.821%ileNVD2026-09-15
CVE-2026-56942In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could HIGH8.820%ileNVD2026-09-15
CVE-2026-56974In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. ThHIGH8.820%ileNVD2026-09-15
CVE-2026-56997In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This cHIGH8.820%ileNVD2026-09-15
CVE-2026-58683In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead toHIGH8.820%ileNVD2026-09-15
CVE-2026-58710In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. ThHIGH8.820%ileNVD2026-09-15
CVE-2026-91711Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrHIGH8.824%ileNVD2026-09-15
CVE-2026-15579An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usernHIGH8.838%ileNVD2026-09-18
CVE-2026-93452snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wrHIGH8.741%ileNVD2026-09-18
CVE-2026-92786LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wrHIGH8.53%ileNVD2026-09-16
CVE-2026-84546An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH8.44%ileNVD2026-09-14
CVE-2026-55301In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead tHIGH8.40%ileNVD2026-09-15
CVE-2026-63388Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX acceptHIGH8.44%ileMicrosoft2026-08-11
CVE-2026-63638OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH8.315%ileNVD2026-09-18
CVE-2026-86107The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betweeHIGH8.229%ileNVD2026-09-16
CVE-2026-86145PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursivHIGH8.231%ileMicrosoft2026-09-08
CVE-2026-70456rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()HIGH8.234%ileMicrosoft2026-08-11
CVE-2026-70458rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED HandlingHIGH8.234%ileMicrosoft2026-08-11
CVE-2026-70461rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from EntryHIGH8.246%ileMicrosoft2026-08-11
CVE-2026-11728IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.147%ileNVD2026-09-15
CVE-2026-10027IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow wheHIGH8.131%ileNVD2026-09-18
CVE-2026-55200libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cHIGH8.190%ileMicrosoft2026-06-09
CVE-2024-53427decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which haHIGH8.129%ileMicrosoft2025-02-11
CVE-2026-55343In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This couHIGH8.012%ileNVD2026-09-15
CVE-2026-56967In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proHIGH8.02%ileNVD2026-09-15
CVE-2026-90948A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer oveHIGH7.814%ileNVD2026-09-14
CVE-2026-90949A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-baseHIGH7.814%ileNVD2026-09-14
CVE-2026-90947A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does notHIGH7.83%ileNVD2026-09-14
CVE-2026-65344An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH7.84%ileNVD2026-09-14
CVE-2026-84505An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mHIGH7.86%ileNVD2026-09-14
CVE-2026-84511An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mHIGH7.86%ileNVD2026-09-14
CVE-2026-84515An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mHIGH7.84%ileNVD2026-09-14
CVE-2026-84575An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mHIGH7.84%ileNVD2026-09-14
CVE-2026-0199In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. ThisHIGH7.80%ileNVD2026-09-15
CVE-2026-19885OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alHIGH7.87%ileNVD2026-09-15
CVE-2026-55323In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This HIGH7.80%ileNVD2026-09-15
CVE-2026-55351In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of priviHIGH7.80%ileNVD2026-09-15
CVE-2026-56945In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privileHIGH7.80%ileNVD2026-09-15
CVE-2026-57014In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing HIGH7.80%ileNVD2026-09-15
CVE-2026-92177pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alloHIGH7.87%ileNVD2026-09-15
CVE-2026-92179pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alloHIGH7.87%ileNVD2026-09-15
CVE-2026-89894In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the VHIGH7.86%ileNVD2026-09-16
CVE-2026-89965In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below thHIGH7.86%ileNVD2026-09-16
CVE-2026-89967In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for cHIGH7.85%ileNVD2026-09-16
CVE-2026-24073Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.HIGH7.86%ileNVD2026-09-17
CVE-2026-24074Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operatHIGH7.86%ileNVD2026-09-17
CVE-2026-25280Memory corruption when processing escape handling flow with insufficient user buffer sizes.HIGH7.82%ileNVD2026-09-17
CVE-2026-90118In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompreHIGH7.86%ileNVD2026-09-17
CVE-2026-90133In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_iHIGH7.89%ileNVD2026-09-17
CVE-2026-90295cpufreq: imx6q: fix out-of-bounds write when probed more than onceHIGH7.812%ileMicrosoft2026-09-08
CVE-2026-54692SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. PHIGH7.84%ileNVD2026-09-17
CVE-2026-63419OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.812%ileNVD2026-09-18
CVE-2026-63422OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.84%ileNVD2026-09-18
CVE-2026-61714FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.HIGH7.84%ileNVD2026-09-18
CVE-2026-13732Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elfHIGH7.82%ileMicrosoft2026-08-11
CVE-2025-68973In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leadiHIGH7.84%ileMicrosoft2025-12-09
CVE-2026-55693Vim: Out-of-bounds Write in Spell File Word CountHIGH7.82%ileMicrosoft2026-06-09
CVE-2026-57455Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argumentHIGH7.82%ileMicrosoft2026-06-09
CVE-2025-38183net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()HIGH7.86%ileMicrosoft2025-07-08
CVE-2025-21785arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo arrayHIGH7.819%ileMicrosoft2025-02-11
CVE-2025-26598Xorg: xwayland: out-of-bounds write in createpointerbarrierclient()HIGH7.834%ileMicrosoft2025-02-11
CVE-2026-91948FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handliHIGH7.750%ileNVD2026-09-15
CVE-2026-67549OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.618%ileNVD2026-09-18
CVE-2025-0624Grub2: net: out-of-bounds write in grub_net_search_config_file()HIGH7.671%ileMicrosoft2025-02-11
CVE-2026-6507Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processingHIGH7.541%ileMicrosoft2026-04-14
CVE-2026-55958Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessageHIGH7.538%ileMicrosoft2026-06-09
CVE-2026-6325Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listHIGH7.522%ileMicrosoft2026-06-09
CVE-2026-84444libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heHIGH7.433%ileNVD2026-09-18
CVE-2026-64752A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, maHIGH7.34%ileNVD2026-09-14
CVE-2026-84611An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH7.33%ileNVD2026-09-14
CVE-2026-54634Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld HIGH7.317%ileNVD2026-09-17
CVE-2026-64736An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS HIGH7.16%ileNVD2026-09-14
CVE-2026-86901An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. MHIGH7.12%ileNVD2026-09-14
CVE-2026-91951FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_currHIGH7.128%ileNVD2026-09-15
CVE-2026-31505iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()HIGH7.13%ileMicrosoft2026-04-14
CVE-2025-24528In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large updateHIGH7.143%ileMicrosoft2026-01-13
CVE-2026-58701In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lHIGH7.00%ileNVD2026-09-15
CVE-2026-58734In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This couldHIGH7.00%ileNVD2026-09-15
CVE-2026-91097HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH7.051%ileNVD2026-09-16
CVE-2026-93015BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP streamHIGH7.016%ileNVD2026-09-17
CVE-2026-94054Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.HIGH7.020%ileNVD2026-09-19
CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_editHIGH7.03%ileMicrosoft2026-09-08
CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemetaHIGH7.03%ileMicrosoft2026-09-08
CVE-2025-40331sctp: Prevent TOCTOU out-of-bounds writeHIGH7.09%ileMicrosoft2025-12-09
CVE-2025-68284libceph: prevent potential out-of-bounds writes in handle_auth_session_key()HIGH7.047%ileMicrosoft2025-12-09
CVE-2026-53059dm log: fix out-of-bounds write due to region_count overflowHIGH7.04%ileMicrosoft2026-06-09
CVE-2026-93451snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that alloMEDIUM6.922%ileNVD2026-09-18
CVE-2026-77396PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parserMEDIUM6.93%ileNVD2026-09-18
CVE-2026-14986The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGEMEDIUM6.88%ileNVD2026-09-14
CVE-2026-89729HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_featureMEDIUM6.829%ileMicrosoft2026-09-08
CVE-2026-55317In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to locaMEDIUM6.70%ileNVD2026-09-15
CVE-2026-55332In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to locaMEDIUM6.70%ileNVD2026-09-15
CVE-2026-55365In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lMEDIUM6.70%ileNVD2026-09-15
CVE-2026-56972In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to locaMEDIUM6.70%ileNVD2026-09-15
CVE-2026-56989In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local eMEDIUM6.70%ileNVD2026-09-15
CVE-2026-57035In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local eMEDIUM6.70%ileNVD2026-09-15
CVE-2026-58773In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This coMEDIUM6.70%ileNVD2026-09-15
CVE-2026-81627A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remMEDIUM6.710%ileNVD2026-09-18
CVE-2025-7519Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds writeMEDIUM6.79%ileMicrosoft2025-07-08
CVE-2026-74498ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is setMEDIUM6.68%ileMicrosoft2026-08-11
CVE-2026-43677An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27,MEDIUM6.524%ileNVD2026-09-14
CVE-2026-43761An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, mMEDIUM6.532%ileNVD2026-09-14
CVE-2026-65395An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.529%ileNVD2026-09-14
CVE-2026-84519An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.525%ileNVD2026-09-14
CVE-2026-84588A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. MoMEDIUM6.515%ileNVD2026-09-14
CVE-2026-86869An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.516%ileNVD2026-09-14
CVE-2026-86882An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.528%ileNVD2026-09-14
CVE-2026-89158PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.MEDIUM6.513%ileMicrosoft2026-09-08
CVE-2026-70457rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()MEDIUM6.532%ileMicrosoft2026-08-11
CVE-2025-0677Grub2: ufs: integer overflow may lead to heap based out-of-bounds write when handling symlinksMEDIUM6.426%ileMicrosoft2025-02-11
CVE-2026-93841vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs indMEDIUM6.315%ileNVD2026-09-18
CVE-2026-74724ipvs: avoid out-of-bounds write in ip_vs_nat_icmpMEDIUM6.32%ileMicrosoft2026-08-11
CVE-2026-84531An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mMEDIUM6.22%ileNVD2026-09-14
CVE-2026-55093Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1MEDIUM6.110%ileNVD2026-09-14
CVE-2026-84619An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mMEDIUM6.12%ileNVD2026-09-14
CVE-2026-59181OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM6.110%ileNVD2026-09-18
CVE-2025-0690Grub2: read: integer overflow may lead to out-of-bounds writeMEDIUM6.152%ileMicrosoft2025-02-11
CVE-2026-80852tls: device: fix out-of-bounds write in tls_append_frag()MEDIUM6.06%ileMicrosoft2026-09-08
CVE-2026-89157PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a MEDIUM5.712%ileMicrosoft2026-09-08
CVE-2026-28968An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.55%ileNVD2026-09-14
CVE-2026-84523An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.55%ileNVD2026-09-14
CVE-2026-84552The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOMEDIUM5.55%ileNVD2026-09-14
CVE-2026-84567The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, MEDIUM5.53%ileNVD2026-09-14
CVE-2026-55892Vim: Out-of-bounds Write in Spell File Prefix DumpMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-82782Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and senMEDIUM5.319%ileNVD2026-09-14
CVE-2026-92880A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/cMEDIUM5.316%ileNVD2026-09-17
CVE-2025-7546GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds writeMEDIUM5.38%ileMicrosoft2025-07-08
CVE-2026-19280IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authMEDIUM5.22%ileNVD2026-09-14
CVE-2026-86876An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.22%ileNVD2026-09-14
CVE-2026-28966An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM4.335%ileNVD2026-09-14
CVE-2026-84526An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM4.327%ileNVD2026-09-14
CVE-2026-91142A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offseLOW3.61%ileNVD2026-09-18
CVE-2026-82327Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist daLOW3.32%ileMicrosoft2026-08-11
CVE-2026-93894In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type LOW2.317%ileNVD2026-09-18
CVE-2026-73639Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRUNKNOWN7%ileNVD2026-09-17
CVE-2026-75892In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context UNKNOWN4%ileNVD2026-09-18
FG-IR-26-123Out-of-bounds access in CAPWAP daemonUNKNOWNFortinet2026-05-12