CVE-2021-3695: GRUB2 PNG loader heap overflow in 16-bit grayscale conversion (d1 += 4 stride bug)
CVE-2021-3695: GRUB2 PNG 16-bit grayscale heap overflow (stride mismatch)
GRUB2 PNG Loader Heap Buffer Overflow Due to Off-by-One in Size Calculation
CVE-2020-10713 BootHole: heap overflow in grub_script_lexer_record
CVE-2020-10713 BootHole: Integer Overflow → Heap Buffer Overflow in GRUB2 Script Lexer (grub-core/script/yylex.l)
CVE-2020-10713 GRUB2 BootHole: YY_FATAL_ERROR Non-Fatal Buffer Overflow
CVE-2024-25062: use-after-free in libxml2 xmlTextReaderRead — missing BACKTRACK state guard on XInclude re-expansion
CVE-2024-25062 libxml2 use-after-free in xmlTextReaderValidateEntity
libxml2 CVE-2024-25062: Use-after-free in xmlTextReaderRead during DTD validation with XInclude
libxml2 CVE-2023-29469: Hash function fails to validate string length
CVE-2021-3518: Use-after-free in libxml2 xmlXIncludeAddNode (xinclude.c)
CVE-2021-3518: Use-after-free in libxml2 XInclude recursive processing
CVE-2022-40304: libxml2 dict corruption via entity reference cycle (ent->content[0]=0 on dict-owned memory)
CVE-2022-40304: libxml2 dict corruption from entity reference cycles
CVE-2022-40304: Dict Corruption via Entity Reference Cycles in libxml2
CVE-2022-40303: Integer overflow in libxml2 xmlSAX2Text → heap buffer overflow on large XML text nodes
CVE-2022-40303: libxml2 integer overflow with XML_PARSE_HUGE in xmlParseEntityValue and friends
CVE-2022-40303: Integer overflow in libxml2 CDATA parsing buffer growth
CVE-2023-0286: Type confusion in OpenSSL GENERAL_NAME_cmp for X.400 addresses — ASN1_STRING* parsed but treated as ASN1_TYPE*
CVE-2023-0286: X.509 GeneralName Type Confusion in OpenSSL 3.0.7