在 embedded-graphics 库的 0.8.2 及更早版本中发现了一个安全漏洞。该漏洞影响了 文件中 函数。对参数 进行特定操作可能导致整数溢出。该攻击可远程发起。项目方已通过 Issue 报告提前得知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | embedded-graphics | 0.8.0 |
cpe:2.3:a:embedded-graphics:embedded-graphics:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90596 | 6.5 MEDIUM | embedded-graphics image_raw.rs new/bytes_per_row integer overflow |
| CVE-2026-90577 | 5.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow |
| CVE-2026-90578 | 5.3 MEDIUM | GPAC MP4Box list.c gf_list_count use after free |
| CVE-2026-90529 | 3.5 LOW | DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting |
| CVE-2026-90573 | 3.3 LOW | GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference |
| CVE-2026-90576 | 3.3 LOW | GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference |
No comments yet