Total
3550 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-67376 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-16 | N/A | 7.5 HIGH |
| Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-19389 | 2026-09-16 | N/A | 7.1 HIGH | ||
| Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed. | |||||
| CVE-2026-65391 | 2026-09-16 | N/A | 8.8 HIGH | ||
| An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption. | |||||
| CVE-2026-65390 | 2026-09-16 | N/A | 8.8 HIGH | ||
| An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption. | |||||
| CVE-2026-55351 | 2026-09-16 | N/A | 7.8 HIGH | ||
| In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-91746 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-91728 | 2026-09-16 | N/A | 9.6 CRITICAL | ||
| Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-92259 | 2026-09-15 | N/A | 5.5 MEDIUM | ||
| Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238. | |||||
| CVE-2026-92248 | 2026-09-15 | N/A | 7.8 HIGH | ||
| A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution. | |||||
| CVE-2026-86138 | 1 Xmlsoft | 1 Libxml2 | 2026-09-15 | N/A | 6.9 MEDIUM |
| In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | |||||
| CVE-2026-86139 | 1 Xmlsoft | 1 Libxml2 | 2026-09-15 | N/A | 6.9 MEDIUM |
| In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | |||||
| CVE-2026-67641 | 1 Microsoft | 2 Sql Server 2022, Sql Server 2025 | 2026-09-15 | N/A | 6.5 MEDIUM |
| Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. | |||||
| CVE-2026-43788 | 1 Apple | 1 Macos | 2026-09-15 | N/A | 6.6 MEDIUM |
| An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents. | |||||
| CVE-2026-65413 | 2026-09-15 | N/A | 5.5 MEDIUM | ||
| An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause a denial of service. | |||||
| CVE-2026-90596 | 2026-09-15 | 6.4 MEDIUM | 6.5 MEDIUM | ||
| A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-84517 | 2026-09-15 | N/A | 5.5 MEDIUM | ||
| An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination. | |||||
| CVE-2026-84487 | 2026-09-15 | N/A | 6.5 MEDIUM | ||
| An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result in disclosure of process memory. | |||||
| CVE-2026-84536 | 2026-09-15 | N/A | 6.5 MEDIUM | ||
| An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination. | |||||
| CVE-2026-91960 | 2026-09-15 | N/A | 6.5 MEDIUM | ||
| FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection. | |||||
| CVE-2026-84554 | 2026-09-15 | N/A | 5.9 MEDIUM | ||
| An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service. | |||||
