在 libmikmod 3.3.14 版本之前,Impulse Tracker 加载器(load_it.c)中存在一个堆溢出读取漏洞。攻击者可以利用过大的模式数据(patterns)读取相邻的堆内存。攻击者可以提供一个精心构造的 IT 模块文件,其中包含超过 200 行的模式,从而导致 函数读取超出 缓冲区的边界,进而引发应用程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105837 | 7.8 HIGH | libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow |
| CVE-2026-105839 | 7.8 HIGH | libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD |
No comments yet