CWE-197

CWE-197 · 4 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-197, highest CVSS first.

  1. HIGH 7.5CVE-2026-96280public PoC

    The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer …

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-19667

    If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versi…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-101085public PoC

    Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via t…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-76151

    Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excess…

    AI risk analysis on Exploit-DB.ai →