Common Weakness Enumeration

CWE-125

Allowed

Out-of-bounds Read

Abstraction: Base · Status: Draft

The product reads data past the end, or before the beginning, of the intended buffer.

12656 vulnerabilities reference this CWE, most recent first.

CVE-2026-94282 (GCVE-0-2026-94282)

Vulnerability from cvelistv5 – Published: 2026-09-28 08:18 – Updated: 2026-09-30 12:41
VLAI
Title
Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion
Summary
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 12:41 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-28 08:15
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-94282",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T12:41:02.923257Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T12:41:41.238Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "datePublic": "2026-09-28T08:15:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T08:18:13.987Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=cecf160e9731fe01f3632f875f29ffcb598b052a"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-94282",
    "datePublished": "2026-09-28T08:18:13.987Z",
    "dateReserved": "2026-09-21T09:33:25.369Z",
    "dateUpdated": "2026-09-30T12:41:41.238Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-94281 (GCVE-0-2026-94281)

Vulnerability from cvelistv5 – Published: 2026-09-24 16:23 – Updated: 2026-09-24 17:14
VLAI
Title
Out-of-bounds read in libXi's XListInputDevices() class parsing
Summary
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:14 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-24 16:22
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-94281",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:14:08.828973Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:14:17.652Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE-Report-PSIRTSUPT-14718"
        }
      ],
      "datePublic": "2026-09-24T16:22:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T16:23:50.110Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XListInputDevices() class parsing",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-94281",
    "datePublished": "2026-09-24T16:23:50.110Z",
    "dateReserved": "2026-09-21T09:33:25.369Z",
    "dateUpdated": "2026-09-24T17:14:17.652Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93682 (GCVE-0-2026-93682)

Vulnerability from cvelistv5 – Published: 2026-09-25 20:02 – Updated: 2026-09-25 20:38
VLAI
Title
Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
Summary
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 20:37 UTC
CWE
References
Impacted products
Vendor Product Version
PHP Group PHP Affected: 8.2.* , < 8.2.34 (semver)
Affected: 8.3.* , < 8.3.35 (semver)
Affected: 8.4.* , < 8.4.26 (semver)
Affected: 8.5.* , < 8.5.11 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93682",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T20:37:51.434446Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-25T20:38:14.346Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "ext-standard",
          "product": "PHP",
          "vendor": "PHP Group",
          "versions": [
            {
              "lessThan": "8.2.34",
              "status": "affected",
              "version": "8.2.*",
              "versionType": "semver"
            },
            {
              "lessThan": "8.3.35",
              "status": "affected",
              "version": "8.3.*",
              "versionType": "semver"
            },
            {
              "lessThan": "8.4.26",
              "status": "affected",
              "version": "8.4.*",
              "versionType": "semver"
            },
            {
              "lessThan": "8.5.11",
              "status": "affected",
              "version": "8.5.*",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Ilia Alshanetsky"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Jordi Kroon"
        },
        {
          "lang": "en",
          "type": "remediation reviewer",
          "value": "David Carlier"
        },
        {
          "lang": "en",
          "type": "remediation reviewer",
          "value": "Xinchen Hui"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eWhen the HTTP stream wrapper follows a redirect and the response carries a \u003ccode\u003eLocation\u003c/code\u003e header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.\u003c/p\u003e"
            }
          ],
          "value": "When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T20:02:11.467Z",
        "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "shortName": "php"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
    "assignerShortName": "php",
    "cveId": "CVE-2026-93682",
    "datePublished": "2026-09-25T20:02:11.467Z",
    "dateReserved": "2026-09-18T14:18:02.748Z",
    "dateUpdated": "2026-09-25T20:38:14.346Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93545 (GCVE-0-2026-93545)

Vulnerability from cvelistv5 – Published: 2026-09-24 16:20 – Updated: 2026-09-24 17:14
VLAI
Title
Out-of-bounds read in libXi's XListInputDevices()
Summary
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:14 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-24 16:18
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93545",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:14:35.552977Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:14:46.750Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "datePublic": "2026-09-24T16:18:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T16:20:35.334Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XListInputDevices()",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-93545",
    "datePublished": "2026-09-24T16:20:35.334Z",
    "dateReserved": "2026-09-18T09:08:10.295Z",
    "dateUpdated": "2026-09-24T17:14:46.750Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93544 (GCVE-0-2026-93544)

Vulnerability from cvelistv5 – Published: 2026-09-24 16:13 – Updated: 2026-09-24 17:16
VLAI
Title
Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
Summary
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:16 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-24 16:11
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93544",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:16:25.106730Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:16:35.659Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "datePublic": "2026-09-24T16:11:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T16:13:29.067Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-93544",
    "datePublished": "2026-09-24T16:13:29.067Z",
    "dateReserved": "2026-09-18T09:08:10.295Z",
    "dateUpdated": "2026-09-24T17:16:35.659Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93543 (GCVE-0-2026-93543)

Vulnerability from cvelistv5 – Published: 2026-09-24 16:09 – Updated: 2026-09-24 17:17
VLAI
Title
Out-of-bounds read in libXi's XI2 class parser
Summary
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:16 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-24 16:06
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93543",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:16:58.657195Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:17:07.094Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "datePublic": "2026-09-24T16:06:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T16:09:51.221Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XI2 class parser",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-93543",
    "datePublished": "2026-09-24T16:09:51.221Z",
    "dateReserved": "2026-09-18T09:08:10.295Z",
    "dateUpdated": "2026-09-24T17:17:07.094Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93542 (GCVE-0-2026-93542)

Vulnerability from cvelistv5 – Published: 2026-09-24 16:03 – Updated: 2026-09-24 17:18
VLAI
Title
Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()
Summary
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:18 UTC
CWE
References
Impacted products
Vendor Product Version
x.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-24 16:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93542",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:18:15.511330Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:18:26.217Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "x.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "datePublic": "2026-09-24T16:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "An o\u003cspan\u003eut-of-bounds read in libXi\u0027s XI2 class parsing via size_classes()\u003c/span\u003e\u003cspan\u003e and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.\u003c/span\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T16:03:00.095Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XI2 class parsing via size_classes() and copy_classes()",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-93542",
    "datePublished": "2026-09-24T16:03:00.095Z",
    "dateReserved": "2026-09-18T09:08:10.294Z",
    "dateUpdated": "2026-09-24T17:18:26.217Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93541 (GCVE-0-2026-93541)

Vulnerability from cvelistv5 – Published: 2026-09-24 15:58 – Updated: 2026-09-24 17:19
VLAI
Title
Out-of-bounds read in libXi's XQueryDeviceState()
Summary
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 17:19 UTC
CWE
References
Impacted products
Vendor Product Version
X.org libXi Affected: 0 , < 1.8.4 (rpm)
    cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93541",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T17:19:51.914504Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T17:19:59.080Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "libXi",
          "product": "libXi",
          "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
          "vendor": "X.org",
          "versions": [
            {
              "lessThan": "1.8.4",
              "status": "affected",
              "version": "0",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.4",
                  "versionStartIncluding": "0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "AISLE in partnership with Red Hat"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "An out\u003cspan\u003e\u003cspan\u003e-of-bounds read in libXi\u0027s XQueryDeviceState() in libXi before 1.8.4 could be used by a\u0026nbsp;\u003c/span\u003e\u003c/span\u003e"
            }
          ],
          "value": "An out-of-bounds read in libXi\u0027s XQueryDeviceState() in libXi before 1.8.4 could be used by a"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T15:58:58.788Z",
        "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "shortName": "suse"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"
        }
      ],
      "source": {
        "defect": [
          "AISLE in partnership with Red Hat"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "Out-of-bounds read in libXi\u0027s XQueryDeviceState()",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
    "assignerShortName": "suse",
    "cveId": "CVE-2026-93541",
    "datePublished": "2026-09-24T15:58:58.788Z",
    "dateReserved": "2026-09-18T09:08:10.294Z",
    "dateUpdated": "2026-09-24T17:19:59.080Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93331 (GCVE-0-2026-93331)

Vulnerability from cvelistv5 – Published: 2026-09-18 01:45 – Updated: 2026-09-18 19:39 X_Open Source
VLAI
Title
GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds
Summary
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 19:39 UTC
CWE
Impacted products
Vendor Product Version
n/a GPAC Affected: 26.08-DEV
Unaffected: abi-16.26
    cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93331",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-18T19:39:32.373766Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-18T19:39:43.691Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "RTP Depacketizer"
          ],
          "product": "GPAC",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "26.08-DEV"
            },
            {
              "status": "unaffected",
              "version": "abi-16.26"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "dutch (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "Out-of-Bounds Read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-119",
              "description": "Memory Corruption",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-18T01:45:14.263Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-406641 | GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/406641"
        },
        {
          "name": "VDB-406641 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/406641/cti"
        },
        {
          "name": "CVE-2026-93331 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-93331"
        },
        {
          "name": "Submit #942834 | GPAC 26.08-DEV Memory Corruption",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/942834"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/gpac/gpac/issues/3868"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/gpac/gpac/commit/6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/gpac/gpac/releases/tag/abi-16.26"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/gpac/gpac/"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-17T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-17T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-17T19:38:59.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-93331",
    "datePublished": "2026-09-18T01:45:14.263Z",
    "dateReserved": "2026-09-17T17:33:55.195Z",
    "dateUpdated": "2026-09-18T19:39:43.691Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93306 (GCVE-0-2026-93306)

Vulnerability from cvelistv5 – Published: 2026-09-25 14:21 – Updated: 2026-09-26 22:51
VLAI
Title
This Power System update is being released to address
Summary
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 15:11 UTC
CWE
References
URL Tags
https://www.ibm.com/support/pages/node/7289331 vendor-advisorypatch
Impacted products
Vendor Product Version
IBM Server Firmware Affected: FW1120.00 , ≤ FW1120.01 (custom)
Affected: FW1110.00 , ≤ FW1110.31 (custom)
Affected: FW1060.00 , ≤ FW1060.81 (custom)
Affected: FW950.00 , ≤ FW950.H3 (custom)
    cpe:2.3:a:ibm:server_firmware:fw1120.00:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1120.00.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1120.01:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1120.01.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1110.00:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1110.00.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1110.31:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1110.31.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1060.00:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1060.00.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1060.81:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw1060.81.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw950.00:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw950.00.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw950.h3:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:server_firmware:fw950.h3.0:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93306",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T15:11:12.282953Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-26T22:51:18.861Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:server_firmware:fw1120.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1120.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1120.01:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1120.01.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1110.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1110.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1110.31:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1110.31.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1060.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1060.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1060.81:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw1060.81.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw950.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw950.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw950.h3:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:server_firmware:fw950.h3.0:*:*:*:*:*:*:*"
          ],
          "product": "Server Firmware",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "FW1120.01",
              "status": "affected",
              "version": "FW1120.00",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "FW1110.31",
              "status": "affected",
              "version": "FW1110.00",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "FW1060.81",
              "status": "affected",
              "version": "FW1060.00",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "FW950.H3",
              "status": "affected",
              "version": "FW950.00",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.\u003c/p\u003e"
            }
          ],
          "value": "IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds Read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T14:21:42.440Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7289331"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers with the products below should install FW1120.02(1120_171), FW1110.32(1110_138) or newer to remediate this vulnerability.\u003c/p\u003e\u003cp\u003ePower 11\u003cbr/\u003e1) IBM Power System E1180 (9080-HEU)\u003c/p\u003e\u003cp\u003eCustomers with the products below should install FW1060.82(1060_189) or newer to remediate this vulnerability.\u003c/p\u003e\u003cp\u003ePower 10\u003cbr/\u003e1) IBM Power System E1080 (9080-HEX)\u003c/p\u003e\u003cp\u003eCustomers with the products below should install FW950.H4(950_236) or newer to remediate this vulnerability.\u003c/p\u003e\u003cp\u003ePower 9\u003cbr/\u003e1) IBM Power System S922 (9009-22G)\u003cbr/\u003e2) IBM Power System H922 (9223-22S)\u003cbr/\u003e3) IBM Power System S914 (9009-41G)\u003cbr/\u003e4) IBM Power System S924 (9009-42G)\u003cbr/\u003e5) IBM Power System H924 (9223-42S)\u003cbr/\u003e6) IBM Power System E950 (9040-MR9)\u003cbr/\u003e7) IBM Power System E980 (9080-M9S)\u003c/p\u003e\u003cp\u003eThe images mentioned above can be located at IBM Fix Central : \u003ca href=\"https://www.ibm.com/support/fixcentral/\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/\u003c/a\u003e\u003c/p\u003e"
            }
          ],
          "value": "Customers with the products below should install FW1120.02(1120_171), FW1110.32(1110_138) or newer to remediate this vulnerability.\n\n\n\nPower 11\n1) IBM Power System E1180 (9080-HEU)\n\n\n\nCustomers with the products below should install FW1060.82(1060_189) or newer to remediate this vulnerability.\n\n\n\nPower 10\n1) IBM Power System E1080 (9080-HEX)\n\n\n\nCustomers with the products below should install FW950.H4(950_236) or newer to remediate this vulnerability.\n\n\n\nPower 9\n1) IBM Power System S922 (9009-22G)\n2) IBM Power System H922 (9223-22S)\n3) IBM Power System S914 (9009-41G)\n4) IBM Power System S924 (9009-42G)\n5) IBM Power System H924 (9223-42S)\n6) IBM Power System E950 (9040-MR9)\n7) IBM Power System E980 (9080-M9S)\n\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/"
        }
      ],
      "title": "This Power System update is being released to address",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eProtect access to the network interface by operating it on a private network or behind a firewall.\u003c/p\u003e"
            }
          ],
          "value": "Protect access to the network interface by operating it on a private network or behind a firewall."
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-93306",
    "datePublished": "2026-09-25T14:21:42.440Z",
    "dateReserved": "2026-09-17T17:01:08.321Z",
    "dateUpdated": "2026-09-26T22:51:18.861Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation MIT-5
Implementation

Strategy: Input Validation

  • Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
  • When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
  • Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
  • To reduce the likelihood of introducing an out-of-bounds read, ensure that you validate and ensure correct calculations for any length argument, buffer size calculation, or offset. Be especially careful of relying on a sentinel (i.e. special character such as NUL) in untrusted inputs.
Mitigation
Architecture and Design

Strategy: Language Selection

Use a language that provides appropriate memory abstractions.

CAPEC-540: Overread Buffers

An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.