CWE-131

High likelihood

Incorrect Calculation of Buffer Size

Parent: CWE-682 - Incorrect Calculation

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

174 vulnerabilities with CWE-131
CVE-2026-41676 CRITICAL
rust-openssl 0.9.27-0.10.77 - Memory Corruption
CVSS 9.8
CVE-2026-1949 CRITICAL
Incorrect calculation of buffer size on the stack in AS320T
CVSS 9.8
CVE-2026-41197 CRITICAL
Brillig: Heap corruption in foreign call results with nested tuple arrays
CVE-2026-29645 HIGH
NEMU <v2025.12.r2 - Instruction Validation Flaw
CVSS 7.5
CVE-2026-27820 LOW
zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
CVE-2026-40918 MEDIUM
Gimp: gimp: denial of service via crafted pvr image file
CVSS 5.5
CVE-2026-20911 CRITICAL
LibRaw < Commit 0b56545 - Buffer Overflow
CVSS 9.8
CVE-2026-33987 HIGH
FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write
CVSS 7.1
CVE-2026-33986 HIGH
FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
CVSS 7.5
CVE-2026-33985 MEDIUM
FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
CVSS 5.9
CVE-2026-33984 HIGH
FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
CVSS 7.5
CVE-2026-31970 HIGH
HTSlib BGZF index file reader has a heap buffer overflow
CVSS 8.1
CVE-2026-28686 MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Buffer Overflow
CVSS 6.8
CVE-2026-20049 HIGH
Cisco ASA/FTD - DoS
CVSS 7.7
CVE-2026-2738 MEDIUM
ovpn-dco-win 2.8.0 - Buffer Overflow
CVE-2026-1188 CRITICAL
Eclipse Omr < 0.8.0 - Buffer Overflow
CVSS 9.8
CVE-2026-22791 MEDIUM
Opencryptoki - Buffer Overflow
CVSS 6.6
CVE-2026-21503 MEDIUM
Color Iccdev < 2.3.1.2 - NULL Pointer Dereference
CVSS 6.1
CVE-2025-33216 MEDIUM
Nvidia Snap-4 Container - Denial of Service
CVSS 6.8
CVE-2025-33124 MEDIUM
IBM DB2 12.1.0.0 - Buffer Overflow
CVSS 6.5
CVE-2025-62550 HIGH
Microsoft Azure Monitor Agent < 1.35.9 - Out-of-Bounds Write
CVSS 8.8
CVE-2025-66216 CRITICAL
AIS-catcher <0.64 - Buffer Overflow
CVSS 9.8
CVE-2025-61661 MEDIUM
GRUB - DoS
CVSS 4.8
CVE-2025-27074 HIGH
Product <Version - Memory Corruption
CVSS 8.8
CVE-2025-33126 MEDIUM
IBM DB2 High Performance Unload - DoS
CVSS 6.5
Details
Vulnerabilities 174
Exploit Likelihood High