<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Integer Overflow (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/int-overflow.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/int-overflow-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Integer Overflow (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-37462 – An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37462</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37462</strong></p>
  <p>An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45686 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45686</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45686</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0095 – In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0095</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0095</strong></p>
  <p>In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48595 – In multiple locations, there is a possible way to achieve code execution due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48595</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48595</strong></p>
  <p>In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37228 – FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37228</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37228</strong></p>
  <p>FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() return value. A remote unauthenticated attacker can send a single SCTP message with payload >= 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is re…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9998 – Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9998</guid>
    <pubDate>Thu, 28 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9998</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9968 – Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9968</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9968</strong></p>
  <p>Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9966 – Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9966</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9966</strong></p>
  <p>Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9960 – Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9960</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9960</strong></p>
  <p>Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9909 – Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9909</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9909</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10019 – Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10019</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10019</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10015 – Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10015</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10015</strong></p>
  <p>Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10009 – Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10009</guid>
    <pubDate>Thu, 28 May 2026 23:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10009</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46198 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46198</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46198</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: fix integer overflow on buff_pos  Fixing an integer overflow present in batadv_iv_ogm_send_to_if. The size check is done using the int type in batadv_iv_ogm_aggr_packet whereas the buff_pos variable uses the s16 type. This could lead to an out-of-bound read.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46062 – In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46062</guid>
    <pubDate>Wed, 27 May 2026 14:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46062</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ntfs3: fix integer overflow in run_unpack() volume boundary check  The volume boundary check `lcn + len > sbi->used.bitmap.nbits` uses raw addition which can wrap around for large lcn and len values, bypassing the validation.  Use check_add_overflow() as is already done for the adjacent prev_lcn + dlcn and vcn64 + len checks add…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46039 – In the Linux kernel, the following vulnerability has been resolved:

rxgk: Fix p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46039</guid>
    <pubDate>Wed, 27 May 2026 14:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46039</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxgk: Fix potential integer overflow in length check  Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket.  Rather than rounding up the value to be tested (which might overflow), round down the size of the available data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44983 – smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44983</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44983</strong></p>
  <p>smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe code from the caller. This vulnerability is fixed in 2.6.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48691 – FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48691</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48691</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48690 – FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48690</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48690</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_pkthdr_t)) + sizeof(fastnetmon_pcap_file_header_t)' using unsigned int (32-bit) arithmetic. With max_cap…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39834 – When writing data larger than 4GB in a single Write call on an SSH channel, an i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39834</guid>
    <pubDate>Fri, 22 May 2026 04:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39834</strong></p>
  <p>When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43495 – In the Linux kernel, the following vulnerability has been resolved:

net: wwan: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43495</guid>
    <pubDate>Thu, 21 May 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43495</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler  t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44060 – An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44060</guid>
    <pubDate>Thu, 21 May 2026 08:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44060</strong></p>
  <p>An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8631 – A potential security vulnerability has been identified in the HP Linux Imaging a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8631</guid>
    <pubDate>Wed, 20 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8631</strong></p>
  <p>A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24214 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24214</guid>
    <pubDate>Wed, 20 May 2026 04:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24214</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24210 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24210</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24210</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43618 – Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43618</guid>
    <pubDate>Wed, 20 May 2026 02:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43618</strong></p>
  <p>Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8956 – Integer overflow in the Networking: JAR component. This vulnerability was fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8956</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8956</strong></p>
  <p>Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8954 – Incorrect boundary conditions, integer overflow in the Audio/Video component. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8954</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8954</strong></p>
  <p>Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8949 – Integer overflow in the Widget: Win32 component. This vulnerability was fixed in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8949</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8949</strong></p>
  <p>Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8507 – Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8507</guid>
    <pubDate>Sun, 17 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8507</strong></p>
  <p>Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws.  When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44673 – libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44673</guid>
    <pubDate>Thu, 14 May 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44673</strong></p>
  <p>libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8577 – Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8577</guid>
    <pubDate>Thu, 14 May 2026 20:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8577</strong></p>
  <p>Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8573 – Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8573</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8573</strong></p>
  <p>Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8534 – Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.77...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8534</guid>
    <pubDate>Thu, 14 May 2026 20:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8534</strong></p>
  <p>Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8532 – Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8532</guid>
    <pubDate>Thu, 14 May 2026 20:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8532</strong></p>
  <p>Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8519 – Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8519</guid>
    <pubDate>Thu, 14 May 2026 20:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8519</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8510 – Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8510</guid>
    <pubDate>Thu, 14 May 2026 20:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8510</strong></p>
  <p>Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44637 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44637</guid>
    <pubDate>Thu, 14 May 2026 20:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44637</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From  to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character with no upper bound check. Once pos_x approaches INT_MAX, the expression "pos_x + repeat_count" us…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44636 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44636</guid>
    <pubDate>Thu, 14 May 2026 20:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44636</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From  to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no upper bound. width and height are multiplied as plain int when computing the allo…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43909 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43909</guid>
    <pubDate>Thu, 14 May 2026 20:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43909</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside SwapRGBABytes() causes the function to compute a large negative pointer offset when processing kABGR DPX images with large dimensions. The immediate crash is an o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43908 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43908</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43908</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a large negative pointer offset into the output buffer, producing an out-of-bounds write that crashes th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43907 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43907</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43907</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a heap-based out-of-bounds write when processing crafted DPX image files. The function computes buffer sizes using 32-bit signed integer arithmet…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42268 – ModSecurity is an open source, cross platform web application firewall (WAF) eng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42268</guid>
    <pubDate>Tue, 12 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42268</strong></p>
  <p>ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42896 – Integer overflow or wraparound in Windows DWM Core Library allows an authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42896</guid>
    <pubDate>Tue, 12 May 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42896</strong></p>
  <p>Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35415 – Integer overflow or wraparound in Windows Storage Spaces Controller allows an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35415</guid>
    <pubDate>Tue, 12 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35415</strong></p>
  <p>Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34644 – After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34644</guid>
    <pubDate>Tue, 12 May 2026 18:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34644</strong></p>
  <p>After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34640 – Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Ove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34640</guid>
    <pubDate>Tue, 12 May 2026 18:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34640</strong></p>
  <p>Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34336 – Integer overflow or wraparound in Windows DWM Core Library allows an authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34336</guid>
    <pubDate>Tue, 12 May 2026 18:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34336</strong></p>
  <p>Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20753 – Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20753</guid>
    <pubDate>Tue, 12 May 2026 17:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20753</strong></p>
  <p>Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerab…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34963 – barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabiliti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34963</guid>
    <pubDate>Mon, 11 May 2026 23:19:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34963</strong></p>
  <p>barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffe…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42046 – libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42046</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42046</strong></p>
  <p>libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution. This…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28952 – An integer overflow was addressed with improved input validation. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28952</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28952</strong></p>
  <p>An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7568 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7568</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7568</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6664 – An integer overflow in network packet parsing code in PgBouncer before 1.25.2 by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6664</guid>
    <pubDate>Sat, 09 May 2026 01:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6664</strong></p>
  <p>An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43407 – In the Linux kernel, the following vulnerability has been resolved:

libceph: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43407</guid>
    <pubDate>Fri, 08 May 2026 15:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43407</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()  This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEPH_MSG_AUTH_REPLY. In ceph_handle_auth_reply(), the value of the payload_len field of such a message is stored in a variable of type int. A val…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41142 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41142</guid>
    <pubDate>Thu, 07 May 2026 04:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41142</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7973 – Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7973</guid>
    <pubDate>Wed, 06 May 2026 19:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7973</strong></p>
  <p>Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7903 – Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7903</guid>
    <pubDate>Wed, 06 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7903</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7896 – Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7896</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7896</strong></p>
  <p>Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37459 – An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37459</guid>
    <pubDate>Mon, 04 May 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37459</strong></p>
  <p>An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7736 – A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7736</guid>
    <pubDate>Mon, 04 May 2026 07:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7736</strong></p>
  <p>A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7598 – A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7598</guid>
    <pubDate>Fri, 01 May 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7598</strong></p>
  <p>A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37540 – OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37540</guid>
    <pubDate>Fri, 01 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37540</strong></p>
  <p>OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq, i.MX), large values can cause the product to wrap around to a small value.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37537 – collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37537</guid>
    <pubDate>Fri, 01 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37537</strong></p>
  <p>collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-bounds write in Transport Protocol Data Transfer handling. At line 23: uint8_t index = data[0] - 1. When data[0] (sequence number from CAN frame) is 0, index underflows to 255. Subsequent write at tp_dt->data[255*7 + i-1] reaches offset 1791, exceeding the MAX_…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-37534 – Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e53...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37534</guid>
    <pubDate>Fri, 01 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-37534</strong></p>
  <p>Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer,allows attackers to write to arbitrary memory via crafted sequence number from the CAN frame.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31707 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31707</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31707</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate response sizes in ipc_validate_msg()  ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fields from the daemon response to a fixed struct size in unsigned int arithmetic.  Three cases can overflow:    KSMBD_EVENT_RPC_REQUEST:       msg_sz =…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33845 – A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33845</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33845</strong></p>
  <p>A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7424 – Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7424</guid>
    <pubDate>Wed, 29 Apr 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7424</strong></p>
  <p>Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single crafted DHCPv6 packet.         The issue is present whenever DHCPv6 is enabled.…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41605 – Integer Overflow or Wraparound vulnerability in Apache Thrift.

This issue affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41605</guid>
    <pubDate>Tue, 28 Apr 2026 10:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41605</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in Apache Thrift.  This issue affects Apache Thrift: before 0.23.0.  Users are recommended to upgrade to version 0.23.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41602 – Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41602</guid>
    <pubDate>Tue, 28 Apr 2026 10:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41602</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation  This issue affects Apache Thrift: before 0.23.0.  Users are recommended to upgrade to version 0.23.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41416 – PJSIP is a free and open source multimedia communication library written in C. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41416</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41416</strong></p>
  <p>PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31649 – In the Linux kernel, the following vulnerability has been resolved:

net: stmmac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31649</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31649</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: fix integer underflow in chain mode  The jumbo_frm() chain-mode implementation unconditionally computes      len = nopaged_len - bmax;  where nopaged_len = skb_headlen(skb) (linear bytes only) and bmax is BUF_SIZE_8KiB or BUF_SIZE_2KiB.  However, the caller stmmac_xmit() decides to invoke jumbo_frm() based on skb->l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31633 – In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31633</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31633</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix integer overflow in rxgk_verify_response()  In rxgk_verify_response(), there's a potential integer overflow due to rounding up token_len before checking it, thereby allowing the length check to be bypassed.  Fix this by checking the unrounded value against len too (len is limited as the response must fit in a single U…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31607 – In the Linux kernel, the following vulnerability has been resolved:

usbip: vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31607</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31607</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usbip: validate number_of_packets in usbip_pack_ret_submit()  When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets from the network PDU. This value is subsequently used as the loop bound in usbip_recv_iso() and usbip_pad_iso() to iterate over urb->iso_fram…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33999 – A flaw was found in the X.Org X server. This integer underflow vulnerability, sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33999</guid>
    <pubDate>Thu, 23 Apr 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33999</strong></p>
  <p>A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6773 – Denial-of-service due to integer overflow in the Graphics: WebGPU component. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6773</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6773</strong></p>
  <p>Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41445 – KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41445</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41445</strong></p>
  <p>KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc() to allocate an undersized buffer. Attackers can trigger heap buffer overflow by providing crafted…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5720 – miniupnpd contains an integer underflow vulnerability in SOAPAction header parsi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5720</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5720</strong></p>
  <p>miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27297 – Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27297</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27297</strong></p>
  <p>Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27296 – Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27296</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27296</strong></p>
  <p>Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33020 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33020</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33020</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel co…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33019 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33019</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33019</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative val…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27907 – Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27907</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27907</strong></p>
  <p>Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32316 – jq is a command-line JSON processor. An integer overflow vulnerability exists th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32316</guid>
    <pubDate>Mon, 13 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32316</strong></p>
  <p>jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25208 – Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25208</guid>
    <pubDate>Mon, 13 Apr 2026 05:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25208</strong></p>
  <p>Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4154 – GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4154</guid>
    <pubDate>Sat, 11 Apr 2026 01:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4154</strong></p>
  <p>GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of XPM files. The issue results from the l…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4151 – GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4151</guid>
    <pubDate>Sat, 11 Apr 2026 01:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4151</strong></p>
  <p>GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of ANI files. The issue results from the l…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4150 – GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4150</guid>
    <pubDate>Sat, 11 Apr 2026 01:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4150</strong></p>
  <p>GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of PSD files. The issue results from the l…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5477 – An integer overflow existed in the wolfCrypt CMAC implementation, that could be ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5477</guid>
    <pubDate>Fri, 10 Apr 2026 06:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5477</strong></p>
  <p>An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The function wc_CmacUpdate used the guard `if (cmac->totalSz != 0)` to skip XOR-chaining on the first block (where digest is all-zeros and the XOR is a no-op). However, totalSz is word32 and wraps to zero after 2^28 block flushes (4 GiB), causing the guard to erroneously discard the live…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5188 – An integer underflow issue exists in wolfSSL when parsing the Subject Alternativ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5188</guid>
    <pubDate>Fri, 10 Apr 2026 04:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5188</strong></p>
  <p>An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the internal length counter to wrap during parsing. This results in incorrect handling of certificate data. The issue is limited to configurations using the original ASN.1 parsi…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40046 – Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40046</guid>
    <pubDate>Thu, 09 Apr 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40046</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.  The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions.   This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5444 – A heap buffer overflow vulnerability exists in the PAM image parsing logic. When...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5444</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5444</strong></p>
  <p>A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen values can cause an integer overflow during buffer size calculation, resulting in the allocation of a small buffer followed by a much larger write operation during pixel p…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5442 – A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimensio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5442</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5442</strong></p>
  <p>A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5912 – Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5912</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5912</strong></p>
  <p>Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5910 – Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5910</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5910</strong></p>
  <p>Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5909 – Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5909</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5909</strong></p>
  <p>Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5908 – Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5908</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5908</strong></p>
  <p>Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5870 – Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5870</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5870</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5859 – Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5859</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5859</strong></p>
  <p>Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5859">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
