<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:15:46 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-57268 — GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-57268</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GeoVision Inc. GeoWebPlayer&lt;/p&gt;
&lt;p&gt;GeoWebPlayer (also called &amp;#34;Web Plugin&amp;#34; in the GV-VMS documentation and &amp;#34;WS Player&amp;#34; for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.&lt;/p&gt;
&lt;p&gt;The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.&lt;/p&gt;
&lt;p&gt;### saveVideo command index-out-of-bound&lt;/p&gt;
&lt;p&gt;When sending the `saveVideo` command, the `index` field is extracted from the websocket message [1]. Then without checking the range of the index, it is used to trigger a CriticalSection ([2]) and releases it [3]. The release function call ([3]) is executed using a function pointer which will be read out of bounds potentially leading to code execution:&lt;/p&gt;
&lt;p&gt;v6 = get_entry(a2, &amp;#34;index&amp;#34;);&lt;/p&gt;
&lt;p&gt;result = json_is_value_int(v6);&lt;/p&gt;
&lt;p&gt;if ( (_BYTE)result )&lt;/p&gt;
&lt;p&gt;{&lt;/p&gt;
&lt;p&gt;v8 = get_entry(a2, &amp;#34;index&amp;#34;);&lt;/p&gt;
&lt;p&gt;index = json_value_to_int(&amp;amp;v8-&amp;gt;value);  // [1]&lt;/p&gt;
&lt;p&gt;result = CCriticalSection::EnterCritSection(&amp;amp;this-&amp;gt;crit_sections[index]);  //[2]&lt;/p&gt;
&lt;p&gt;if ( result )&lt;/p&gt;
&lt;p&gt;{&lt;/p&gt;
&lt;p&gt;if ( this-&amp;gt;array…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GeoVision Inc. GeoWebPlayer&lt;/p&gt;
&lt;p&gt;GeoWebPlayer (also called &amp;#34;Web Plugin&amp;#34; in the GV-VMS documentation and &amp;#34;WS Player&amp;#34; for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.&lt;/p&gt;
&lt;p&gt;The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.&lt;/p&gt;
&lt;p&gt;### saveVideo command index-out-of-bound&lt;/p&gt;
&lt;p&gt;When sending the `saveVideo` command, the `index` field is extracted from the websocket message [1]. Then without checking the range of the index, it is used to trigger a CriticalSection ([2]) and releases it [3]. The release function call ([3]) is executed using a function pointer which will be read out of bounds potentially leading to code execution:&lt;/p&gt;
&lt;p&gt;v6 = get_entry(a2, &amp;#34;index&amp;#34;);&lt;/p&gt;
&lt;p&gt;result = json_is_value_int(v6);&lt;/p&gt;
&lt;p&gt;if ( (_BYTE)result )&lt;/p&gt;
&lt;p&gt;{&lt;/p&gt;
&lt;p&gt;v8 = get_entry(a2, &amp;#34;index&amp;#34;);&lt;/p&gt;
&lt;p&gt;index = json_value_to_int(&amp;amp;v8-&amp;gt;value);  // [1]&lt;/p&gt;
&lt;p&gt;result = CCriticalSection::EnterCritSection(&amp;amp;this-&amp;gt;crit_sections[index]);  //[2]&lt;/p&gt;
&lt;p&gt;if ( result )&lt;/p&gt;
&lt;p&gt;{&lt;/p&gt;
&lt;p&gt;if ( this-&amp;gt;array…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-57268</guid>
    </item>
  </channel>
</rss>
