Threats Tagged 'cwe-122'
View all threats tagged with 'cwe-122'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-122'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-46752: CWE-122 Heap-based Buffer Overflow in Apache Software Foundation Apache KvrocksCVE-2026-46752 0 Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. Join the discussion | CVE Database V5 | 06/25/2026, 08:00:18 UTC Added: 06/25/2026, 09:16:11 UTC |
CVE-2026-12244: CWE-190: Integer Overflow or Wraparound in NLnet Labs NSDCVE-2026-12244 0 CVE-2026-12244 is a high-severity integer overflow vulnerability in NLnet Labs NSD version 4.14.0. When NSD is configured as a secondary server for a DNS zone, a malicious primary server can send an AXFR response containing a specially crafted SVCB resource record with an rdata size of 65512. This triggers an integer overflow in a 16-bit unsigned variable used for memory allocation, leading to a heap overflow. The vulnerability allows an attacker to perform a controlled remote code execution by overwriting up to 65509 bytes of memory. Join the discussion | CVE Database V5 | 06/25/2026, 05:24:08 UTC Added: 06/25/2026, 06:46:04 UTC |
CVE-2026-9149: Heap-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10CVE-2026-9149 0 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS). Join the discussion | GCVE Database | 05/20/2026, 23:34:56 UTC Added: 06/24/2026, 16:59:31 UTC |
CVE-2026-45696: CWE-122: Heap-based Buffer Overflow in AcademySoftwareFoundation openexrCVE-2026-45696 0 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo_imp function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared width as the iteration count. The codestream embedded in the EXR chunk can declare different (smaller) tile/line dimensions than the EXR header advertises, but ht_undo_impl() does not validate this — it pulls width 32-bit samples from cur_line->i32[] without checking the OpenJPH line buffer's actual length. A crafted EXR file produces a 4-byte heap-buffer-overflow READ immediately after a buffer allocated by ojph::local::codestream::finalize_alloc(). The bug is reachable through the standard scanline-decode entry point used by every consumer of exr_decoding_run/Imf::checkOpenEXRFile, including thumbnailers, asset pipelines, and the exrcheck utility — i.e. any application that opens untrusted EXR files. The result is a deterministic crash (DoS) and potential adjacent-heap leak. This issue has been fixed in version 3.4.12. Join the discussion | CVE Database V5 | 06/18/2026, 20:31:56 UTC Added: 06/18/2026, 21:20:21 UTC |
CVE-2026-2467: CWE-122 Heap-based Buffer Overflow in RTI Connext ProfessionalCVE-2026-2467 0 Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*. Join the discussion | CVE Database V5 | 06/17/2026, 17:17:04 UTC Added: 06/17/2026, 17:35:20 UTC |
CVE-2026-42055: CWE-122 Heap-based Buffer Overflow in F5 NGINX Open SourceCVE-2026-42055 0 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Join the discussion | CVE Database V5 | 06/17/2026, 14:04:32 UTC Added: 06/17/2026, 15:07:24 UTC |
CVE-2026-47747: CWE-122: Heap-based Buffer Overflow in leejet stable-diffusion.cppCVE-2026-47747 0 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opcode handler. The issue was caused by sign confusion on the opcode length field. A crafted .ckpt file could trigger memcpy with a very large length derived from a negative signed value, causing immediate heap corruption. The issue has been resolved in version master-584-0a7ae07. If developers are unable to immediately update their applications they can work around this issue by only loading .ckpt checkpoint files from trusted sources and preferring trusted model sources and safer formats such as .safetensors where possible. Join the discussion | CVE Database V5 | 06/16/2026, 18:32:33 UTC Added: 06/16/2026, 19:30:49 UTC |
CVE-2026-47964: Heap-based Buffer Overflow (CWE-122) in Adobe DNG SDKCVE-2026-47964 0 DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Join the discussion | CVE Database V5 | 06/16/2026, 16:32:57 UTC Added: 06/16/2026, 18:30:54 UTC |
CVE-2026-47749: CWE-787: Out-of-bounds Write in leejet stable-diffusion.cppCVE-2026-47749 0 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the SHORT_BINUNICODE opcode handler. The issue was caused by sign confusion on the opcode length field. A crafted .ckpt file could trigger memcpy with a very large length derived from a negative signed value, causing immediate heap corruption. Any application using affected stable-diffusion.cpp releases to load untrusted .ckpt model files could be vulnerable. A malicious checkpoint file could cause heap corruption through memcpy with an attacker-controlled length. This may lead to process crash and could potentially be leveraged for code execution depending on heap layout. The attack requires the victim or application to load a .ckpt file from an untrusted source, such as a downloaded model from a model sharing site. The issue has been resolved in version master-584-0a7ae07. If developers are unable to immediately update their applications they can work around this issue by not loading .ckpt checkpoint files from untrusted sources, and referring to trusted model sources and safer formats such as .safetensors where possible. Join the discussion | CVE Database V5 | 06/16/2026, 17:23:20 UTC Added: 06/16/2026, 18:30:54 UTC |
CVE-2026-8484: CWE-122 Heap-based Buffer Overflow in FuseSource jansiCVE-2026-8484 0 A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment. Join the discussion | CVE Database V5 | 06/16/2026, 10:32:14 UTC Added: 06/16/2026, 11:30:18 UTC |
Showing 1 to 10 of 86 results