Export limit exceeded: 26676 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (26676 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-63275 | 1 The Document Foundation | 1 Libreoffice | 2026-09-22 | 7.3 High |
| LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has. | ||||
| CVE-2026-63276 | 1 The Document Foundation | 1 Libreoffice | 2026-09-22 | 7.3 High |
| LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up. | ||||
| CVE-2026-63279 | 1 The Document Foundation | 1 Libreoffice | 2026-09-22 | 6.1 Medium |
| LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory outside the palette. In fixed versions the palette index is limited to the entries present. | ||||
| CVE-2026-69681 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-22 | 8 High |
| Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-94424 | 1 Moore Threads | 1 Mtt S80 Driver Package | 2026-09-22 | 8.8 High |
| A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-25294 | 1 Qualcomm | 151 Cologne, Cologne Firmware, Congo and 148 more | 2026-09-22 | 7.4 High |
| Transient DOS while parsing frame during channel usage. | ||||
| CVE-2026-25284 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.3 High |
| Information Disclosure when a pointer is reused after being deallocated. | ||||
| CVE-2026-25283 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 8.8 High |
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | ||||
| CVE-2026-25282 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.9 High |
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-81642 | 1 Nlnetlabs | 1 Unbound | 2026-09-22 | 9.8 Critical |
| In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound. | ||||
| CVE-2026-69714 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-22 | 8 High |
| Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69715 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-22 | 9.8 Critical |
| Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-64198 | 2 Measx, Ni | 2 Dasylab, Dasylab | 2026-09-22 | 7.8 High |
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | ||||
| CVE-2026-64199 | 2 Measx, Ni | 2 Dasylab, Dasylab | 2026-09-22 | 7.8 High |
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | ||||
| CVE-2026-64200 | 2 Measx, Ni | 2 Dasylab, Dasylab | 2026-09-22 | 7.8 High |
| There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0. | ||||
| CVE-2020-6851 | 5 Debian, Fedoraproject, Oracle and 2 more | 13 Debian Linux, Fedora, Georaster and 10 more | 2026-09-22 | 7.5 High |
| OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. | ||||
| CVE-2026-69760 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-22 | 7.5 High |
| Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-30802 | 1 Rti | 1 Connext Micro | 2026-09-22 | 8.2 High |
| Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*. | ||||
| CVE-2026-7300 | 1 Rti | 1 Connext Professional | 2026-09-22 | 6.5 Medium |
| Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.3, from 6.1.2 before 6.1.*. | ||||
| CVE-2026-3894 | 1 Rti | 1 Connext Professional | 2026-09-22 | 9.1 Critical |
| Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*. | ||||