Security Risk Category
Memory Corruption Security Risks — Page 6
Published vulnerability pages connected to Memory Corruption. Each page keeps one canonical URL and focused remediation guidance.
409 published Memory Corruption risks
Memory Corruption risks
Showing 181–216 of 409 published risks.
CVE-2026-55029 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55031 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55048 in Microsoft 365 Apps
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55053 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55058 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55120 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55121 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-55122 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-55130 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55131 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55136 in Microsoft 365 Apps
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55137 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55138 in Microsoft 365 Apps
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-55141 in Microsoft 365 Apps
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55898 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-58633 in Microsoft Windows
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-58634 in Microsoft Windows
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-15764 in Google Chrome
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Updated Jul 16, 2026
CVE-2026-15765 in Google Chrome
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Updated Jul 16, 2026
CVE-2026-15766 in Google Chrome
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15767 in Google Chrome
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15770 in Google Chrome
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15772 in Google Chrome
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15773 in Google Chrome
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15774 in Google Chrome
Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15776 in Google Chrome
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15777 in Google Chrome
Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-33443 in Absolute Secure Access
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
Updated Jul 16, 2026
CVE-2026-40953 in Absolute Secure Access
CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.
Updated Jul 16, 2026
CVE-2026-44041 UltraVNC Wide String Out-of-Bounds Read
UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp:204, the vncWc2Mb() function passes a caller-supplied WCHAR pointer to wcslen() before any bounds check. If the caller provides a wide-character buffer that is not properly NUL-terminated, wcslen() reads past the end of the buffer until it encounters a NUL wchar, resulting in an out-of-bounds read. Under typical Win32 API usage this requires an abnormal caller contract. Impact is limited to a potential information disclosure from adjacent memory regions or a process crash (denial of service) if the over-read crosses a page boundary.
Updated Jul 15, 2026
CVE-2026-44042 UltraVNC Repeater Base64 Decode Off-by-One
UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentication. In repeater/webgui/webutils.c:817, the wi_uudecode() function checks whether the input length exceeds the output buffer with a strict greater-than comparison (>), while the correct check should be greater-than-or-equal (>=). When strlen(authdata) equals sizeof(decode), the decoded output length (approximately 3/4 of input) does not overflow the buffer in current practice because the outer HTTP request bounds constrain the Authorization header. However, the defective check leaves a latent off-by-one condition that could become exploitable if the buffering constraints change. The current risk is limited to a one-byte write at the boundary of a 1024-byte stack buffer under constrained conditions.
Updated Jul 15, 2026
CVE-2026-7828 UltraVNC Repeater Integer Overflow Vulnerability
UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/settings.c:336, the win_log() function allocates list nodes via malloc(sizeof(struct LIST) + strlen(line)), where line is derived from HTTP request URIs. If strlen(line) is sufficiently large, the addition overflows to a value smaller than sizeof(struct LIST), causing a heap allocation smaller than required. The subsequent strcpy of the full string into the undersized allocation produces a heap buffer overflow. In the current implementation this overflow is bounded by the HTTP receive buffer size (WI_RXBUFSIZE = 153600 bytes, well below SIZE_MAX on 32-bit builds), limiting practical exploitability to a partial heap write. A remote unauthenticated attacker can trigger the theoretical overflow path by sending a maximally-sized URI in an HTTP request to the repeater HTTP port.
Updated Jul 15, 2026
CVE-2026-7829 UltraVNC Repeater Rule Parser Out-of-Bounds Write
UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In repeater/webgui/settings.c:225-272, after strncpy_s copies a rule token into temp1[rule1] (25-byte destination) or temp2/temp3 (16-byte destination), the code unconditionally writes a NUL terminator at temp1[rule1][len] = 0 without clamping len to the destination size. When an authenticated administrator saves a rule with a token length equal to or greater than the destination size, the NUL byte is written one or more bytes past the end of the stack-allocated array, corrupting adjacent stack data. An attacker who has obtained admin credentials (including via CVE-2026-7839 default password) can trigger this to gain code execution on the repeater host.
Updated Jul 15, 2026
CVE-2026-7831 UltraVNC Viewer Off-by-One Stack Overflow
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn[2024], one byte past the end of the stack buffer. A malicious VNC server can trigger this condition by advertising a desktop name of length 2024 in its ServerInit message. On release builds without stack canaries the single-byte NUL overwrite adjacent stack data. On builds with /GS stack protection the canary is corrupted and the process terminates, resulting in denial of service. User interaction (connecting the viewer to the malicious server) is required.
Updated Jul 15, 2026
CVE-2026-7838 UltraVNC Viewer Heap Buffer Overflow Vulnerability
UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, the 4-byte network-supplied reasonLen field (type CARD32) is passed as reasonLen+1 to CheckBufferSize(). Because both operands are unsigned 32-bit, a reasonLen of 0xFFFFFFFF overflows to 0, causing CheckBufferSize to allocate only 256 bytes. The subsequent ReadString(m_netbuf, reasonLen) call then performs ReadExact for the original 4 GiB length into that 256-byte heap buffer. This overflow is reachable via rfbConnFailed (auth-scheme negotiation) and rfbVncAuthFailed (post-handshake) message types without successful authentication. A malicious VNC server, or any man-in-the-middle on the RFB stream, can trigger this condition when the victim viewer connects, potentially resulting in remote code execution as the user running the viewer. The crash was confirmed with AddressSanitizer on a portable reproduction harness (heap-buffer-overflow WRITE at offset 256).
Updated Jul 15, 2026
CVE-2026-7840 UltraVNC Repeater HTTP Buffer Overflow RCE
UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via unchecked sprintf calls. The HTTP receive buffer accepts URIs up to approximately 150 KB (WI_RXBUFSIZE = 153600), so an unauthenticated attacker who can reach the repeater HTTP port (default TCP 80) can overflow hdrbuf by at least 500 bytes with a single HTTP request containing a URI of 1500 bytes or longer, corrupting adjacent .bss-segment globals. The overflow occurs before any authentication check, making it reachable without credentials. A remote, unauthenticated attacker can achieve arbitrary code execution on the host running the repeater.
Updated Jul 15, 2026
