Threats Tagged 'cwe-119'
View all threats tagged with 'cwe-119'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-119'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component. Join the discussion | GCVE Database | 09/16/2026, 19:00:09 UTC Added: 09/17/2026, 02:00:10 UTC |
0 A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.24 is sufficient to fix this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. The affected component should be upgraded. This issue is distinct from CVE-2026-90827. Join the discussion | GCVE Database | 09/16/2026, 18:45:09 UTC Added: 09/17/2026, 02:00:10 UTC |
0 CVE-2026-92178 is a high-severity memory corruption vulnerability in pdfforge PDF Architect version 9.1.83.23106. It arises from improper validation of user-supplied data during PDF file parsing, leading to potential remote code execution. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious page. The vulnerability allows attackers to execute arbitrary code with the privileges of the current process. Join the discussion | CVE Database V5 | 09/15/2026, 18:05:42 UTC Added: 09/15/2026, 18:32:13 UTC |
0 CVE-2026-19886 is a high-severity memory corruption vulnerability in OriginLab Origin Viewer version 9.9.5. It arises from improper validation during the parsing of OGM files, allowing remote attackers to execute arbitrary code if a user opens a malicious file or visits a malicious page. Exploitation requires user interaction. The vulnerability is identified as CWE-119, indicating improper restriction of operations within memory buffer bounds. Join the discussion | CVE Database V5 | 09/15/2026, 18:02:49 UTC Added: 09/15/2026, 18:32:13 UTC |
0 Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Join the discussion | GCVE Database | 09/15/2026, 12:34:15 UTC Added: 09/16/2026, 03:07:57 UTC |
0 A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised. Join the discussion | GCVE Database | 09/14/2026, 21:15:14 UTC Added: 09/15/2026, 01:37:36 UTC |
0 PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields. Loading an invalid, corrupted, or malicious language or acoustic model can therefore cause stack or heap buffer overflows and memory corruption. An attacker who can write to a directory selected by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx later loads; users of PocketSphinx 5prealpha have no backported patch and must migrate to the fixed release. This issue is fixed in version 5.1.1. Join the discussion | CVE Database V5 | 09/14/2026, 20:07:50 UTC Added: 09/14/2026, 20:17:55 UTC |
0 A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Join the discussion | GCVE Database | 09/13/2026, 23:45:10 UTC Added: 09/14/2026, 01:36:27 UTC |
0 A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded. Join the discussion | GCVE Database | 09/13/2026, 18:30:09 UTC Added: 09/14/2026, 00:36:38 UTC |
0 A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | GCVE Database | 09/13/2026, 17:15:10 UTC Added: 09/14/2026, 00:36:42 UTC |
Showing 1 to 10 of 175 results