Security Risk Category

Memory Corruption Security Risks — Page 10

Published vulnerability pages connected to Memory Corruption. Each page keeps one canonical URL and focused remediation guidance.

409 published Memory Corruption risks

Memory Corruption risks

Showing 325–360 of 409 published risks.

highEPSS 0.004

CVE-2026-57992 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57992browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58276 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58276browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58283 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58283browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58285 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58285browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58287 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58287browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58288 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58288browsermicrosoftmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.004

CVE-2026-58289 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58289browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-58290 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58290browsermicrosoftmemory-corruption

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58294 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58294browsermicrosoftmemory-corruption

Updated Jul 13, 2026

highEPSS 0.004

CVE-2026-58295 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-58295browsermicrosoftmemory-corruption

Updated Jul 13, 2026

low

CVE-2026-14759 radare2 vulnerability

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.

CVE-2026-14759javamemory-corruption

Updated Jul 13, 2026

low

CVE-2026-14760 radare2 vulnerability

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

CVE-2026-14760memory-corruption

Updated Jul 13, 2026

low

CVE-2026-14788 radare2 vulnerability

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.

CVE-2026-14788memory-corruption

Updated Jul 13, 2026

low

CVE-2026-14789 radare2 vulnerability

A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to address this issue.

CVE-2026-14789memory-corruption

Updated Jul 13, 2026

highEPSS 0.002

CVE-2026-58380 gimp vulnerability

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVE-2026-58380remote-code-executiondenial-of-servicememory-corruption

Updated Jul 13, 2026

medium

CVE-2025-59615 fastconnect 6700 firmware vulnerability

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.

CVE-2025-59615memory-corruption

Updated Jul 13, 2026

medium

CVE-2025-59616 fastconnect 6700 firmware vulnerability

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

CVE-2025-59616memory-corruption

Updated Jul 13, 2026

medium

CVE-2025-59617 fastconnect 6700 firmware vulnerability

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

CVE-2025-59617memory-corruption

Updated Jul 13, 2026

medium

CVE-2026-21368 fastconnect 6700 firmware vulnerability

Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

CVE-2026-21368memory-corruption

Updated Jul 13, 2026

medium

CVE-2026-21369 fastconnect 6200 firmware vulnerability

Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

CVE-2026-21369memory-corruption

Updated Jul 13, 2026

medium

CVE-2026-21370 fastconnect 6700 firmware vulnerability

Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

CVE-2026-21370memory-corruption

Updated Jul 13, 2026

high

CVE-2026-21379 aqt1000 firmware vulnerability

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

CVE-2026-21379memory-corruption

Updated Jul 13, 2026

mediumEPSS 0.001

CVE-2026-21384 fastconnect 6700 firmware vulnerability

Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

CVE-2026-21384memory-corruption

Updated Jul 13, 2026

highEPSS 0.001

CVE-2026-25268 wsa8835 firmware vulnerability

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

CVE-2026-25268memory-corruption

Updated Jul 13, 2026

highEPSS 0.001

CVE-2026-25271 cologne firmware vulnerability

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

CVE-2026-25271memory-corruption

Updated Jul 13, 2026

mediumEPSS 0.004

CVE-2026-33799 junos vulnerability

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP. Memory usage can be monitored using the following command: user@device> show system processes extensive | match snmpd This issue affects: Junos OS: * all versions before 21.2R3-S8; * from 21.4 before 21.4R3-S7; * from 22.1 before 22.1R3-S6; * from 22.2 before 22.2R3-S4; * from 22.3 before 22.3R3-S3; * from 22.4 before 22.4R3-S2; * from 23.2 before 23.2R2; * from 23.4 before 23.4R2. Junos OS Evolved: * all versions before 21.2R3-S8-EVO; * from 21.4 before 21.4R3-S7-EVO; * all versions of 22.1-EVO, * from 22.2 before 22.2R3-S4-EVO; * from 22.3 before 22.3R3-S3-EVO; * all versions of 22.4-EVO, * from 23.2 before 23.2R2-EVO; * from 23.4 before 23.4R2-EVO.

CVE-2026-33799memory-corruption

Updated Jul 13, 2026

mediumEPSS 0.002

CVE-2026-56373 imagemagick vulnerability

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

CVE-2026-56373memory-corruption

Updated Jul 13, 2026

mediumEPSS 0.001

CVE-2026-59857 Vim vulnerability

Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.

CVE-2026-59857linuxdenial-of-servicememory-corruption

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-53877 Django vulnerability

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVE-2026-53877pythonweb-applicationinformation-disclosuredenial-of-service

Updated Jul 12, 2026

highEPSS 0.004

CVE-2026-58469 GNU Wget vulnerability

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

CVE-2026-58469linuxnetwork-securityinformation-disclosurememory-corruption

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-58471 GNU Wget vulnerability

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.

CVE-2026-58471linuxnetwork-securitymemory-corruption

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-58472 GNU Wget vulnerability

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVE-2026-58472linuxnetwork-securityinput-validationmemory-corruption

Updated Jul 12, 2026

highEPSS 0.003

CVE-2026-60002 openssh vulnerability

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVE-2026-60002network-securitymemory-corruption

Updated Jul 12, 2026

high

CVE-2026-13126 pdf editor vulnerability

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.

CVE-2026-13126pdf-editormemory-corruption

Updated Jul 12, 2026

high

CVE-2026-13127 pdf editor vulnerability

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.

CVE-2026-13127pdf-editormemory-corruption

Updated Jul 12, 2026

high

CVE-2026-13128 pdf editor vulnerability

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.

CVE-2026-13128npmpdf-editormemory-corruption

Updated Jul 12, 2026