WhisperX tag archive

#Heap Buffer Overflow

This page collects WhisperX intelligence signals tagged #Heap Buffer Overflow. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (4)

The Lab · 2026-04-06 05:26:58 · GitHub Issues

1. Critical Heap Buffer Overflow in RHEL 9 Java Package (CVE-2025-65018) - Libpng Vulnerability Patched

A critical heap buffer overflow vulnerability, tracked as CVE-2025-65018, has been patched in the `java-17-openjdk-headless` package for Red Hat Enterprise Linux 9. The flaw originates in the upstream libpng library, a core component for processing PNG image files. Specifically, versions 1.6.0 through 1.6.50 of libpng ...

The Lab · 2026-04-07 18:27:30 · GitHub Issues

2. Electron Security Alert: Critical Heap Buffer Overflow in NativeImage Functions (CVE-2024-46993)

A critical security vulnerability in the Electron framework exposes applications to potential remote code execution via a heap buffer overflow. The flaw, tracked as CVE-2024-46993, resides in the `nativeImage.createFromPath()` and `nativeImage.createFromBuffer()` functions. Any Electron program utilizing these function...

The Lab · 2026-04-30 23:54:11 · GitHub Issues

3. SQLite concat_ws() Integer Overflow Triggers 4GB Heap Overflow, Arbitrary Code Execution Possible

A critical integer overflow vulnerability in SQLite's widely-deployed database engine has been identified, raising serious concerns across the technology industry. The flaw, catalogued as CVE-2025-3277, resides in the `concat_ws()` function and can trigger a heap buffer overflow of approximately 4GB, potentially enabli...

The Lab · 2026-05-14 12:48:18 · r/netsec

4. NGINX Heap Buffer Overflow in Rewrite Module Sparks RCE Concern — CVE-2026-42945 Details Surface

A critical heap buffer overflow vulnerability has been identified in NGINX's rewrite module, bearing the designation CVE-2026-42945. The flaw enables potential remote code execution (RCE) and traces its roots to a vulnerability that has existed unpatched for approximately 18 years. Security researchers have published a...