Total
3145 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68787 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. | |||||
| CVE-2026-68786 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-68785 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 4.9 MEDIUM |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-68775 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-86142 | 1 Xmlsoft | 1 Libxml2 | 2026-09-15 | N/A | 6.9 MEDIUM |
| In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | |||||
| CVE-2026-67643 | 1 Microsoft | 2 Sql Server 2022, Sql Server 2025 | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-67642 | 1 Microsoft | 1 Sql Server 2025 | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-67639 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-83978 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-15 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-67638 | 1 Microsoft | 1 Sql Server 2025 | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-67631 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-45761 | 2026-09-15 | N/A | 3.3 LOW | ||
| Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow while Suricata is loading signatures. The issue is reached during rule parsing/loading rather than by network traffic alone. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, preprocess rules to check that frames are all lowercase and/or only load trusted rulesets. | |||||
| CVE-2026-77482 | 1 Microsoft | 2 Sql Server 2017, Sql Server 2019 | 2026-09-15 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-77486 | 1 Microsoft | 2 Sql Server 2017, Sql Server 2019 | 2026-09-15 | N/A | 8.8 HIGH |
| Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-91088 | 2026-09-15 | 4.3 MEDIUM | 4.8 MEDIUM | ||
| A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component. | |||||
| CVE-2026-91086 | 2026-09-15 | 7.5 HIGH | 6.3 MEDIUM | ||
| A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 can resolve this issue. The name of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended. | |||||
| CVE-2026-90577 | 2026-09-15 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded. | |||||
| CVE-2026-90439 | 2026-09-15 | N/A | 6.5 MEDIUM | ||
| NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |||||
| CVE-2026-79591 | 2026-09-15 | N/A | 7.8 HIGH | ||
| A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index. | |||||
| CVE-2026-39919 | 2026-09-15 | N/A | 9.8 CRITICAL | ||
| Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution. | |||||
