Export limit exceeded: 389970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 49954 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (49954 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57160 1 Pjsip 1 Pjproject 2026-09-08 N/A
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.
CVE-2026-57159 1 Pjsip 1 Pjproject 2026-09-08 N/A
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.
CVE-2026-57165 1 Pjsip 1 Pjproject 2026-09-08 N/A
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_up_down() in cli_telnet.c). This affects only applications that enable the telnet CLI front-end (same gating as the related CLI issue). The line-redraw sequence for a recalled history entry can accumulate more data than a fixed-size stack buffer holds, which may lead to application termination. Exploitation requires access to the unauthenticated telnet CLI, which already permits arbitrary CLI commands, so the additional impact is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 628b716.
CVE-2026-86138 1 Xmlsoft 1 Libxml2 2026-09-08 6.9 Medium
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-86140 1 Xmlsoft 1 Libxml2 2026-09-08 8 High
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVE-2026-70465 1 Fortinet 2 Forticlient, Forticlientwindows 2026-09-08 7.3 High
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
CVE-2026-70466 1 Fortinet 2 Fortios, Fortiweb 2026-09-08 4.8 Medium
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
CVE-2026-71407 1 Fortinet 3 Fortios, Fortipam, Fortiproxy 2026-09-08 5.1 Medium
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
CVE-2026-78517 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 8.8 High
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78522 1 Microsoft 6 365 Apps, Office 2019, Office 2021 and 3 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-80079 1 Microsoft 6 365 Apps, Office 2019, Office 2021 and 3 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-80088 1 Microsoft 9 365 Apps, Microsoft 365, Office 2016 and 6 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-80090 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-83949 1 Microsoft 6 365 Apps, Office 2019, Office 2021 and 3 more 2026-09-08 5.5 Medium
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-83951 1 Microsoft 6 365 Apps, Office 2019, Office 2021 and 3 more 2026-09-08 5.5 Medium
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78506 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 5.5 Medium
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78502 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-18796 1 Nordic Semiconductor Asa 1 Nrf5340 2026-09-08 N/A
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
CVE-2026-85201 1 Eclipse 1 Ankaios 2026-09-08 N/A
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
CVE-2026-72976 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 5 Medium
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.