Threats Tagged 'cwe-122'
View all threats tagged with 'cwe-122'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-122'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19259: Heap-based Buffer Overflow in MZ Automation libiec61850CVE-2026-19259 0 A heap-based buffer overflow vulnerability exists in MZ Automation libiec61850 up to version 1.6.1 in the function MmsMapping_varAccessSpecToObjectReference within the MMS Protocol Workflow component. The vulnerability arises from manipulation of the argument GetNamedVariableListAttributesResponse.itemId. Exploitation requires local access and no user interaction. The issue has been publicly disclosed, but no patch or vendor response is currently available. Join the discussion | GCVE Database | 08/08/2026, 06:00:09 UTC Added: 08/08/2026, 14:51:49 UTC |
CVE-2026-18938: Heap-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10CVE-2026-18938 0 A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems. Join the discussion | GCVE Database | 08/07/2026, 08:19:08 UTC Added: 08/07/2026, 15:17:42 UTC |
VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerabilityCVE-2026-18497 0 A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The vulnerability resides in the glyph data parsing path. An attacker can craft a malformed TTF file with an inflated endPtsOfContours value and truncate the remaining glyph data. When an application utilizing stb_truetype.h (such as various game engines or graphics software) attempts to load, bake, or render this malformed font via stbtt_GetGlyphShape(), the parser will attempt to read past the end of the glyph data buffer, triggering the out-of-bounds read. Join the discussion | CERT/CC | 08/07/2026, 15:33:18 UTC Added: 08/07/2026, 14:24:06 UTC |
CVE-2026-70638: Integer Overflow or Wraparound in ggml-org llama.cppCVE-2026-70638 0 llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a malicious model file or JNI call to trigger heap corruption and achieve denial of service or arbitrary code execution on Android applications using the LLaMA-Android binding. Join the discussion | CVE Database V5 | 08/06/2026, 15:35:08 UTC Added: 08/06/2026, 22:13:33 UTC |
CVE-2026-67867: n/aCVE-2026-67867 0 CVE-2026-67867 is a buffer overflow vulnerability in Systerel S2OPC version 1.7.3. It allows a remote attacker to cause a denial of service by exploiting the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data. The vulnerability has a high severity with a CVSS score of 7.5 and does not impact confidentiality or integrity but affects availability. Join the discussion | GCVE Database | 08/05/2026, 00:00:00 UTC Added: 08/06/2026, 18:16:34 UTC |
CVE-2026-67873: n/aCVE-2026-67873 0 A heap-based buffer overflow vulnerability exists in lib60870-C version 2.4.0 within the server-side FileSegment ASDU encoding path. The flaw arises because the FileSegment_encode() function only validates the standalone segment length but does not check the remaining capacity of the current ASDU frame before encoding, potentially leading to memory corruption. Join the discussion | GCVE Database | 08/05/2026, 00:00:00 UTC Added: 08/06/2026, 18:16:32 UTC |
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility:… (CVE-2026-34502)CVE-2026-34502 0 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. Join the discussion | GCVE Database | 08/06/2026, 15:32:45 UTC Added: 08/06/2026, 18:16:21 UTC |
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. (CVE-2026-34501)CVE-2026-34501 0 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. Join the discussion | GCVE Database | 08/06/2026, 15:32:45 UTC Added: 08/06/2026, 18:16:21 UTC |
CVE-2026-34502: CWE-122 Heap-based Buffer Overflow in Apache Software Foundation Apache Portable Runtime UtilityCVE-2026-34502 0 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. Join the discussion | CVE Database V5 | 08/06/2026, 14:31:07 UTC Added: 08/06/2026, 14:41:57 UTC |
CVE-2026-34501: CWE-122 Heap-based Buffer Overflow in Apache Software Foundation Apache Portable Runtime UtilityCVE-2026-34501 0 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. Join the discussion | CVE Database V5 | 08/06/2026, 14:31:48 UTC Added: 08/06/2026, 14:41:57 UTC |
Showing 1 to 10 of 147 results