在 32 位系统上,版本 0.8.2 及以下的 embedded-graphics 中存在一个安全弱点。该问题影响了文件 中的 函数。此操作会导致整数溢出(integer overflow)。该漏洞可被远程触发。建议升级受影响的组件以修复该问题。项目方已通过问题报告提前获知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | embedded-graphics | 0.8.0 |
cpe:2.3:a:embedded-graphics:embedded-graphics:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90593 | 7.3 HIGH | embedded-graphics image_raw.rs draw_sub_image integer overflow |
| CVE-2026-90577 | 5.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow |
| CVE-2026-90578 | 5.3 MEDIUM | GPAC MP4Box list.c gf_list_count use after free |
| CVE-2026-90529 | 3.5 LOW | DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting |
| CVE-2026-90573 | 3.3 LOW | GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference |
| CVE-2026-90576 | 3.3 LOW | GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference |
No comments yet