CVE-2026-103629
Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page
CVSS
4.3
Medio
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Publicado: 2 oct 2026 · Última mod.: 3 oct 2026 · CWE-190
0.2%EPSS · 30 días0.2%
2026-10-032026-10-04
Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-79113—2.8%
——1OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.2dCVE-2026-1036214.3 MED6.7%
——2Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-83632—29.4%
——9Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-66837—19.6%
——6Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-935468.8 ALT25.5%
——8Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.3dCVE-2026-1025047.5 ALT31.0%
——9Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.
Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).
Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.3d