在 vgmstream 2117 版本之前发现了一个安全漏洞。该漏洞影响组件 TXTP 文件处理程序(TXTP File Handler)中 src/meta/txtp_parser.c 文件的 parse_params/txtp_parse 函数。漏洞利用可导致越界写入(out-of-bounds write)。攻击者可能通过远程方式发起攻击。相关补丁标识为 4669d37a6af94866f6f0628678f9f90d46954e8b。建议及时应用补丁以修复该问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | vgmstream | r2117 |
cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105251 | 6.3 MEDIUM | vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds |
| CVE-2026-105180 | 6.3 MEDIUM | Jeebase UserService info updateUser dynamically-determined object attributes |
| CVE-2026-105174 | 5.4 MEDIUM | Gerapy Project Management views.py project_create path traversal |
| CVE-2026-105249 | 4.8 MEDIUM | vgmstream TXTP File txtp_process.c make_group_random use after free |
| CVE-2026-105250 | 4.3 MEDIUM | vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero |
No comments yet