Total
3557 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-24210 | 2 Linux, Nvidia | 2 Linux Kernel, Triton Inference Server | 2026-07-24 | N/A | 7.5 HIGH |
| NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service. | |||||
| CVE-2026-33642 | 1 Kovidgoyal | 1 Kitty | 2026-07-24 | N/A | 9.9 CRITICAL |
| Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/Write. An attacker who can write escape sequences to a kitty terminal (e.g., via a malicious file, SSH login banner, or piped content) can supply crafted x_offset/y_offset values that pass the bounds check after wrapping but cause massive out-of-bounds heap memory access in compose_rectangles(). No user interaction is required. No non-default configuration is required. The attacker only needs the ability to produce output in a kitty terminal window. This issue has been fixed in version 0.47.0. | |||||
| CVE-2026-5476 | 1 Nasa | 1 Core Flight System | 2026-07-24 | 4.0 MEDIUM | 4.6 MEDIUM |
| A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A fix is planned for the upcoming version milestone of the project. | |||||
| CVE-2026-6664 | 1 Pgbouncer | 1 Pgbouncer | 2026-07-24 | N/A | 7.5 HIGH |
| An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet. | |||||
| CVE-2026-7568 | 1 Php | 1 Php | 2026-07-24 | N/A | 7.5 HIGH |
| In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process. | |||||
| CVE-2026-39824 | 2026-07-23 | N/A | 3.3 LOW | ||
| NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error. | |||||
| CVE-2026-39834 | 1 Golang | 1 Crypto | 2026-07-23 | N/A | 9.1 CRITICAL |
| When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation. | |||||
| CVE-2026-42627 | 2026-07-23 | N/A | 6.2 MEDIUM | ||
| In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimization. The overflow occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without overflow detection, causing GetNumBytes() to return an understated allocation size. During Optimize()->InferOutputShapes(), the BatchToSpaceNdLayer reads beyond the allocated buffer. | |||||
| CVE-2025-14098 | 2026-07-23 | N/A | 7.8 HIGH | ||
| Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104. | |||||
| CVE-2025-66280 | 1 Qnap | 2 Qts, Quts Hero | 2026-07-23 | N/A | 7.2 HIGH |
| An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later | |||||
| CVE-2026-42974 | 1 Microsoft | 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-07-23 | N/A | 8.1 HIGH |
| Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-47288 | 1 Microsoft | 5 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 2 more | 2026-07-23 | N/A | 7.1 HIGH |
| Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. | |||||
| CVE-2026-44812 | 1 Microsoft | 16 Excel, Powerpoint, Windows 10 1607 and 13 more | 2026-07-23 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-41849 | 1 Vmware | 1 Spring Framework | 2026-07-23 | N/A | 7.5 HIGH |
| An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48. | |||||
| CVE-2026-45592 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-07-23 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-44803 | 1 Microsoft | 16 Excel, Powerpoint, Windows 10 1607 and 13 more | 2026-07-23 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |||||
| CVE-2023-29146 | 2026-07-23 | N/A | 8.2 HIGH | ||
| The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for two different strings by attaching 4GB of data to a string that is less than 4GB in size. | |||||
| CVE-2026-41977 | 2026-07-23 | N/A | 5.0 MEDIUM | ||
| DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-45593 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-07-23 | N/A | 7.8 HIGH |
| Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-42916 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-07-23 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | |||||
