在 vgmstream 版本 r2117 及更早版本中发现了一个安全漏洞。该漏洞影响位于 文件中的 TXTP 文件格式处理组件(TXTP File Handler)的 函数。此漏洞可导致“释放后使用”(use-after-free)错误。攻击需在本地发起。修复补丁标识为:ae37662ad626254ddd96ad69ac263792d7a92024。建议应用该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | vgmstream | r2117 |
cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105251 | 6.3 MEDIUM | vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds |
| CVE-2026-105248 | 6.3 MEDIUM | vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write |
| CVE-2026-105180 | 6.3 MEDIUM | Jeebase UserService info updateUser dynamically-determined object attributes |
| CVE-2026-105174 | 5.4 MEDIUM | Gerapy Project Management views.py project_create path traversal |
| CVE-2026-105250 | 4.3 MEDIUM | vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero |
No comments yet