SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

29 results for “cwe-16” · 0.73 s · cached

Facets · 1 entity types

29 CVEClear type filter
CVE-2025-32717CVE

CVE-2025-32717

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.5%
Match for cwe-16
CVE-2026-5684CVE

CVE-2026-5684

A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the ar…

CVSS 8.0EPSS 0.7%tenda
Match for cwe-16
CVE-2026-3544CVE

CVE-2026-3544

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Hig…

CVSS 8.8EPSS 0.4%
Match for cwe-16
CVE-2026-8531CVE

CVE-2026-8531

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…

CVSS 8.8EPSS 0.3%
Match for cwe-16
CVE-2026-3542CVE

CVE-2026-3542

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sever…

CVSS 8.8EPSS 0.4%
Match for cwe-16
CVE-2026-3914CVE

CVE-2026-3914

Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%
Match for cwe-16
CVE-2026-11281CVE

CVE-2026-11281

Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Ch…

CVSS 5.0EPSS 0.1%google
Match for cwe-16
CVE-2016-2279CVE

CVE-2016-2279

Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via …

CVSS 6.1EPSS 7.6%rockwellautomation
Match for cwe-16
CVE-2026-36817CVE

CVE-2026-36817

Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability…

CVSS 7.5EPSS 0.6%
Match for cwe-16
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.