CWE-131

High likelihood

Incorrect Calculation of Buffer Size

Parent: CWE-682 - Incorrect Calculation

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

209 vulnerabilities with CWE-131
CVE-2026-45812 MEDIUM
Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
CVSS 6.5
CVE-2026-65706 HIGH
FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing
CVSS 7.8
CVE-2026-65705 HIGH
FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()
CVSS 7.8
CVE-2026-45784 HIGH
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVSS 7.1
CVE-2026-55827 HIGH
FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode
CVSS 7.5
CVE-2026-0280 HIGH
PAN-OS: IPv6 Firewall Policy Bypass
CVSS 7.2
CVE-2026-54696 LOW
Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
CVSS 3.7
CVE-2026-53143 HIGH
drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVSS 7.8
CVE-2026-2050 HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-53091 HIGH
net: pull headers in qdisc_pkt_len_segs_init()
CVSS 8.4
CVE-2026-52955 CRITICAL
libceph: Fix potential out-of-bounds access in crush_decode()
CVSS 9.8
CVE-2026-42055 HIGH
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVSS 8.1
CVE-2026-8357 HIGH
The Document Foundation LibreOffice - Heap Buffer Overflow in Calc Formula Compilation
CVSS 7.8
CVE-2026-46521 MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVSS 5.5
CVE-2026-2049 HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-11604 MEDIUM
Openvpn Ovpn-dco-win < 2.5.8 - Heap-based Buffer Overflow
CVE-2026-49841 CRITICAL
FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CVSS 9.8
CVE-2026-42915 MEDIUM
Microsoft Windows TCP/IP - Authorized Adjacent Network Denial of Service
CVSS 5.5
CVE-2026-10701 HIGH
Incorrect boundary conditions in the Graphics: Text component
CVSS 7.5
CVE-2026-44420 HIGH
FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
CVSS 8.8
CVE-2026-43501 CRITICAL
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
CVSS 9.8
CVE-2026-42945 HIGH
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
CVE-2026-40618 HIGH
F5 BIG-IP SSL/TLS - TMM Denial of Service
CVSS 7.5
CVE-2026-44223 MEDIUM
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVSS 6.5
CVE-2026-43302 MEDIUM
drm/v3d: Set DMA segment size to avoid debug warnings
CVSS 5.5
Details
Vulnerabilities 209
Exploit Likelihood High