CVE-2026-47314
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da
CVSS
7.8
High
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: May 19, 2026 · Last modified: Jul 24, 2026 · CWE-787
0.3%EPSS · 30 days0.3%
2026-08-092026-09-06
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-14297——
——0A buffer overflow in the Bluetooth Continuous Glucose
Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
allows an authenticated BLE peer to overflow a 20-byte static buffer into
adjacent BSS memory. The exploitable impact cannot be predetermined - it
is entirely dependent on the linker-assigned BSS layout of the specific
firmware build, which may vary.6hCVE-2026-81738——
——0OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries7hCVE-2026-863137.8 HIG—
——0Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.
This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.12hCVE-2026-07998.7 HIG1.2%
——0In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.2dCVE-2026-860987.4 HIG28.3%
——8ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.3dCVE-2026-860957.8 HIG2.6%
——1Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.3d