Skip to content
Threat Feed

Tag

Memory-Safety

12 briefs RSS
high advisory

Out-of-Bounds Read Vulnerability in Redis Cluster Bus

A vulnerability in the Redis cluster bus packet parser allows remote attackers to trigger an out-of-bounds read via crafted PING, PONG, or MEET packets, resulting in potential information disclosure or denial of service.

Redis vulnerability memory-safety denial-of-service
1c
high advisory

Out-of-Bounds Memory Read in zstd-jni

The zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.

zstd-jni vulnerability memory-safety java
1t 1c updated
high advisory

Out-of-Bounds Read Vulnerability in 92181 markdown Library

An out-of-bounds read vulnerability in the 'lds' function of the 92181 markdown library allows remote attackers to trigger memory access errors via crafted inputs.

markdown vulnerability cve-2026-86303 memory-safety
1c
high advisory

Heap-based Buffer Overflow in FFmpeg hvcC Box Writer

FFmpeg versions prior to commit acf5d7c contain a heap-based buffer overflow in the hvcC box writer that can be triggered during HEVC file muxing, potentially leading to arbitrary code execution.

FFmpeg +2 vulnerability memory-corruption memory-safety
1t 1c
medium advisory

CVE-2026-68160: Out-of-Bounds Read in Ceph ceph_handle_caps

A vulnerability in the Ceph ceph_handle_caps function allows for an out-of-bounds read during the pre-authentication phase, potentially leading to denial-of-service or memory disclosure.

Ceph vulnerability memory-safety
1c
medium threat

Memory Safety Vulnerability in libceph decode_lockers()

CVE-2026-68082 describes two unsafe bare decode operations within the libceph decode_lockers() function that could lead to memory corruption during network data deserialization.

exploited libceph memory-corruption vulnerability storage memory-safety linux ceph
1c updated
high advisory

Heap Out-of-Bounds Read in FreeRDP Glyph Caching

FreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.

FreeRDP vulnerability memory-safety remote-access tls man-in-the-middle
1t 1c
high advisory

Open Babel Uninitialized Pointer Dereference Vulnerability (CVE-2022-42885)

A high-severity memory-safety vulnerability (CVE-2022-42885) in Open Babel's GRO residue parser allows an uninitialized pointer dereference when processing a specially crafted GRO input file, potentially leading to application crash or arbitrary code execution.

Open Babel <= 3.1.1 +1 vulnerability memory-safety cve open-babel
1t 1c
high threat

Open Babel MOL2 Parser Out-of-Bounds Write (CVE-2022-43607)

A memory-safety vulnerability, CVE-2022-43607, in Open Babel's MOL2 parser allows an out-of-bounds write when processing a crafted input file, potentially leading to denial of service or arbitrary code execution.

exploited Open Babel +1 memory-safety vulnerability library cve file-parsing chemistry denial-of-service code-execution
1r 1t 1c
high advisory

Open Babel Has Uninitialized Pointer Dereference in MSI Atom Parser

A memory-safety vulnerability (CVE-2022-44451) in Open Babel's MSI parser allows for an uninitialized pointer dereference when processing a specially crafted MSI input file, affecting versions prior to 3.2.0 and potentially leading to application instability or denial of service when a victim opens a malicious file.

Open Babel chemistry vulnerability memory-safety open-babel cve
1t 1c
high threat

barebox EFI PE Loader Memory-Safety Vulnerabilities (CVE-2026-34963)

barebox versions prior to 2026.04.0 are vulnerable to memory-safety issues in the EFI PE loader (CVE-2026-34963), potentially allowing code execution via malicious EFI PE binaries.

barebox memory-safety heap-overflow bootloader
1r 1t 1c
high advisory

Swift Crypto X-Wing HPKE Decapsulation Vulnerability

The X-Wing decapsulation path in swift-crypto accepts attacker-controlled encapsulated ciphertext bytes without enforcing the required fixed ciphertext length of 1120 bytes, leading to a potential out-of-bounds read.

vulnerability memory-safety swift-crypto
2r 1t