Total
3255 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-10999 | 1 Google | 1 Chrome | 2026-07-22 | N/A | 6.5 MEDIUM |
| Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-49510 | 2026-07-22 | N/A | 6.1 MEDIUM | ||
| Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f. | |||||
| CVE-2026-41521 | 1 Neutrinolabs | 1 Xrdp | 2026-07-22 | N/A | 8.2 HIGH |
| xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a denial of service (DoS) via a process crash. This issue has been fixed in version 0.10.6.1. | |||||
| CVE-2026-16517 | 2026-07-22 | N/A | 2.9 LOW | ||
| A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. | |||||
| CVE-2026-10722 | 1 Cilium | 1 Ebpf | 2026-07-22 | 1.7 LOW | 3.3 LOW |
| A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue. | |||||
| CVE-2026-45686 | 1 Opentelemetry | 1 Ebpf Instrumentation | 2026-07-22 | N/A | 7.5 HIGH |
| OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large <bytes> values and adds the payload delimiter length without checking for overflow. A crafted request with <bytes> set to math.MaxInt or math.MaxInt-1 causes the computed payload length to wrap negative and triggers a runtime panic in LargeBufferReader.Peek. This issue has been patched in version 0.9.0. | |||||
| CVE-2026-37462 | 2026-07-22 | N/A | 7.5 HIGH | ||
| An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | |||||
| CVE-2026-0095 | 1 Google | 1 Android | 2026-07-22 | N/A | 8.0 HIGH |
| In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-0080 | 1 Google | 1 Android | 2026-07-22 | N/A | 6.5 MEDIUM |
| In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-59117 | 1 Microsoft | 1 Terminal | 2026-07-22 | N/A | 7.5 HIGH |
| Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-58594 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 8.8 HIGH |
| Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-58532 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-56194 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-56182 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-54124 | 1 Microsoft | 8 Terminal, Windows 10 21h2, Windows 10 22h2 and 5 more | 2026-07-22 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-54109 | 1 Microsoft | 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more | 2026-07-22 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |||||
| CVE-2026-50347 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-50310 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-22 | N/A | 4.7 MEDIUM |
| Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-50306 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.8 HIGH |
| Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50299 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 6.8 MEDIUM |
| Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | |||||
