Security Risk Category
Memory Corruption Security Risks — Page 7
Published vulnerability pages connected to Memory Corruption. Each page keeps one canonical URL and focused remediation guidance.
409 published Memory Corruption risks
Memory Corruption risks
Showing 217–252 of 409 published risks.
CVE-2026-56372 ImageMagick Heap Buffer Overflow Read Vulnerability
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
Updated Jul 15, 2026
CVE-2026-61857 ImageMagick XMP Use-After-Free Vulnerability
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
Updated Jul 15, 2026
CVE-2026-61861 ImageMagick Use-After-Free Vulnerability
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution.
Updated Jul 15, 2026
CVE-2026-57021 in Junos OS
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon...
Updated Jul 15, 2026
CVE-2026-57025 in Junos OS
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged...
Updated Jul 15, 2026
CVE-2026-55827 in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the...
Updated Jul 15, 2026
CVE-2026-57156 in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT),...
Updated Jul 15, 2026
CVE-2026-57157 in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL terminator in...
Updated Jul 15, 2026
CVE-2026-57158 in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to...
Updated Jul 15, 2026
CVE-2026-55233 in OpenResty
OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to upstream servers,...
Updated Jul 15, 2026
CVE-2026-59837 in FortiProxy
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions,...
Updated Jul 15, 2026
CVE-2026-59840 in FortiProxy
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow attacker to information...
Updated Jul 15, 2026
CVE-2026-55947 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-55949 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has an uninitialized resource issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-56156 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-58596 in Microsoft Edge Chromium
Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.
Updated Jul 15, 2026
CVE-2026-8085 in Rockwell Automation Arena Simulation
Arena Simulation has an out-of-bounds write issue in model.exe that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-8312 in Rockwell Automation Arena Simulation
Arena Simulation has an out-of-bounds write issue in expmt.exe that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-8313 in Rockwell Automation Arena Simulation
Arena Simulation has an out-of-bounds write issue in linker.exe that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-8314 in Rockwell Automation Arena Simulation
Arena Simulation has an out-of-bounds write issue in siman.exe that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-47969 in Adobe Audition
Adobe Audition has an out-of-bounds read issue that can expose memory if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-48309 in Adobe Audition
Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-48365 in Adobe Audition
Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-48368 in Adobe Audition
Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-55054 in Microsoft Excel and Microsoft 365 Apps
Microsoft Excel has an out-of-bounds read issue that can disclose information when a user opens a crafted file.
Updated Jul 15, 2026
CVE-2026-6682 in FatFs
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). Remote delivery is also possible in OTA/update pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Updated Jul 15, 2026
CVE-2026-6687 in FatFs
FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Updated Jul 15, 2026
CVE-2026-6688 in FatFs
FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname can be up to 255 characters; many callers copy it into short fixed buffers without bounds checks, causing overflow. This maps to CWE-120 (Buffer Copy without Checking Size of Input). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Updated Jul 15, 2026
CVE-2026-24266 in NVIDIA Triton Inference Server
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
Updated Jul 15, 2026
CVE-2026-20213 in ClamAV
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-20214 in ClamAV
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-20215 in ClamAV
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-20217 in ClamAV
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-20243 in ClamAV
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-20244 in ClamAV
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Updated Jul 15, 2026
CVE-2026-40467 in GNU awk
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
Updated Jul 15, 2026
