Total
3550 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69584 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-85228 | 2026-09-10 | N/A | 9.1 CRITICAL | ||
| An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above. | |||||
| CVE-2026-88015 | 2026-09-10 | N/A | 5.3 MEDIUM | ||
| rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1. | |||||
| CVE-2026-88035 | 2026-09-10 | N/A | 4.7 MEDIUM | ||
| A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it. | |||||
| CVE-2026-69499 | 2026-09-10 | N/A | 8.8 HIGH | ||
| Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69298 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-10 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-72990 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-10 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-72995 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-10 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-45527 | 2026-09-10 | N/A | 4.3 MEDIUM | ||
| In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-81987 | 3 Adobe, Apple, Microsoft | 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more | 2026-09-10 | N/A | 7.8 HIGH |
| Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-72986 | 2026-09-10 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69608 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69407 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-49919 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-87630 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 4.3 MEDIUM |
| Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87643 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-68552 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src/client/ns_turn_msg.c to wrap when STUN_HEADER_LENGTH is added. The framing layer then consumes only 4 through 16 bytes, treats the remaining bytes as another message, desynchronizes the stream parser, and drops the attacking client's connection. Other clients and the server process are not affected. This issue is fixed in version 4.15.0. | |||||
| CVE-2026-63384 | 2026-09-09 | N/A | N/A | ||
| Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha. | |||||
| CVE-2026-55191 | 2026-09-09 | N/A | N/A | ||
| FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_recalloc to allocate an undersized buffer before YUV420CombineToYUV444 writes using the actual stride and rectangle dimensions. This can cause a client crash and may permit code execution through attacker-influenced heap corruption. This issue is fixed in version 3.27.0. | |||||
| CVE-2026-55648 | 2026-09-09 | N/A | N/A | ||
| FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0. | |||||
