在 vgmstream(最高至 r2117 版本)中检测到一处漏洞。受此漏洞影响的组件为 VAG 文件处理器(VAG File Handler),具体涉及源文件 中的 函数。通过构造恶意操作可导致越界读取(out-of-bounds read)。该漏洞允许远程攻击者利用。修复补丁的版本标识为 。建议安装该补丁以解决此安全问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | vgmstream | r2117 |
cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105248 | 6.3 MEDIUM | vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write |
| CVE-2026-105180 | 6.3 MEDIUM | Jeebase UserService info updateUser dynamically-determined object attributes |
| CVE-2026-105174 | 5.4 MEDIUM | Gerapy Project Management views.py project_create path traversal |
| CVE-2026-105249 | 4.8 MEDIUM | vgmstream TXTP File txtp_process.c make_group_random use after free |
| CVE-2026-105263 | 4.7 MEDIUM | Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side requ |
| CVE-2026-105250 | 4.3 MEDIUM | vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero |
No comments yet