Security Risk Category

Memory Corruption Security Risks — Page 9

Published vulnerability pages connected to Memory Corruption. Each page keeps one canonical URL and focused remediation guidance.

409 published Memory Corruption risks

Memory Corruption risks

Showing 289–324 of 409 published risks.

criticalEPSS 0.003

CVE-2026-14405 in Google Chrome V8

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14405browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14406 in Google Chrome V8

Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

CVE-2026-14406browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14407 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14407browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14408 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14408browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14413 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14413browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14414 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14414browserinput-validationinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14415 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14415browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14416 in Google Chrome Dawn

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14416browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14417 in Google Chrome Dawn

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14417browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14418 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14418browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14419 in Google Chrome Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14419browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14420 in Google Chrome Dawn

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14420browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14421 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14421browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14422 in Google Chrome Tint

Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14422browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14423 in Google Chrome Tint

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14423browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14424 in Google Chrome Dawn

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14424browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14425 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14425browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14426 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14426browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14427 in Google Chrome Skia

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14427browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14428 in Google Chrome Dawn

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14428browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14429 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14429browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14430 in Google Chrome V8

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14430browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14431 in Google Chrome V8

Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14431browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14432 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14432browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

high

CVE-2026-13053 WatchGuard Fireware Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13053network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

high

CVE-2026-13383 fireware vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13383network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

high

CVE-2026-13384 fireware vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13384network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

critical

CVE-2026-10536 curl vulnerability

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

CVE-2026-10536memory-corruption

Updated Jul 14, 2026

criticalEPSS 0.011

CVE-2026-8925 curl vulnerability

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

CVE-2026-8925memory-corruption

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-9080 curl vulnerability

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

CVE-2026-9080memory-corruption

Updated Jul 14, 2026

medium

CVE-2026-14355 php vulnerability

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVE-2026-14355phpmemory-corruption

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-56645 edge chromium vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-56645browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57975 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57975browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57981 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57981browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57984 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57984browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57986 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57986browsermicrosoftmemory-corruption

Updated Jul 14, 2026