Security Risk Category

Memory Corruption Security Risks — Page 8

Published vulnerability pages connected to Memory Corruption. Each page keeps one canonical URL and focused remediation guidance.

409 published Memory Corruption risks

Memory Corruption risks

Showing 253–288 of 409 published risks.

lowEPSS 0.002

CVE-2026-40468 in GNU awk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

CVE-2026-40468linuxinput-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-40469 in GNU awk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

CVE-2026-40469linuxinput-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-40553 in GNU awk

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

CVE-2026-40553linuxdenial-of-servicememory-corruption

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-13221 in Perl

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.

CVE-2026-13221input-validationmemory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57432 in Perl

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.

CVE-2026-57432input-validationinformation-disclosurememory-corruption

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-57433 in Storable for Perl

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

CVE-2026-57433input-validationdenial-of-servicememory-corruptionunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-15685 in Ollama

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

CVE-2026-15685input-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

medium

CVE-2026-59198 in Pillow

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.

CVE-2026-59198pythoninformation-disclosurememory-corruption

Updated Jul 15, 2026

high

CVE-2026-59199 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

CVE-2026-59199pythoninput-validationmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-59205 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

CVE-2026-59205pythonapi-securityinput-validationmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-47967 in Adobe Audition

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47967remote-code-executionmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-47968 in Adobe Audition

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47968remote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-53466 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-53466input-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-55510 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55510input-validationmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55577 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55577input-validationmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55594 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55594input-validationdenial-of-servicememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55597 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

CVE-2026-55597input-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.008

CVE-2026-50521 in Microsoft Edge Chromium

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVE-2026-50521browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14383 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14383browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14384 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14384browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14385 in Google Chrome ANGLE

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14385browsermemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14386 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14386browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14388 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14388browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14390 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14390browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14391 in Google Chrome ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14391browserwindowsinput-validationinformation-disclosure

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14392 in Google Chrome Tint

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14392browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14393 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14393browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14394 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14394browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14395 in Google Chrome V8

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14395browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14396 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14396browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14397 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14397browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14398 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14398browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14399 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14399browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14400 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14400browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14402 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14402browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14403 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14403browserremote-code-executionmemory-corruption

Updated Jul 14, 2026