CWE-823

CWE-823 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-823, highest CVSS first.

  1. LOW 2.5CVE-2026-107570

    heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template.

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-104944

    TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in a denial-of-service con…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-102757public PoC

    An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided wheth…

    AI risk analysis on Exploit-DB.ai →