Total
14834 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-73193 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes per input byte for the longest ':p99999' expansion. The product is computed in STRLEN, which is 32 bits wide on a 32-bit perl build, so a statement of 613,566,757 bytes multiplies to 4,294,967,299, wraps modulo 2^32 to 3, and reserves 19 bytes. The parser then copies the statement out through a raw pointer with no capacity check, writing the whole 585 MB input past the end of the allocation. The 99,999 placeholder limit does not bound this path, which is reached by ordinary non-placeholder content. Any caller that passes an untrusted statement of that length to preparse on a 32-bit perl gets a heap out-of-bounds write of attacker controlled bytes. Builds with a 64-bit STRLEN are not affected, since the wrap there needs a statement of about 2.3 exabytes. | |||||
| CVE-2026-65609 | 2026-08-28 | N/A | N/A | ||
| nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable. | |||||
| CVE-2026-48418 | 1 Adobe | 1 Substance 3d Sampler | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48419 | 1 Adobe | 1 Substance 3d Sampler | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48420 | 1 Adobe | 1 Substance 3d Sampler | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48421 | 1 Adobe | 1 Substance 3d Sampler | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-8247 | 1 Watchguard | 39 Firebox Cloud, Firebox M270, Firebox M290 and 36 more | 2026-08-28 | N/A | 8.8 HIGH |
| An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. | |||||
| CVE-2026-71564 | 1 Adobe | 1 Substance 3d Designer | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48427 | 1 Adobe | 1 Substance 3d Designer | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48426 | 1 Adobe | 1 Substance 3d Designer | 2026-08-28 | N/A | 7.8 HIGH |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48410 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48409 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48408 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48407 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48406 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48405 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48404 | 2 Adobe, Microsoft | 2 Lightroom, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48370 | 1 Adobe | 1 Media Encoder | 2026-08-28 | N/A | 7.8 HIGH |
| Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48369 | 1 Adobe | 1 Premiere Pro | 2026-08-28 | N/A | 7.8 HIGH |
| Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48368 | 3 Adobe, Apple, Microsoft | 3 Audition, Macos, Windows | 2026-08-28 | N/A | 7.8 HIGH |
| Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
