Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9136

Опубликовано: 19 авг. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 7.8
CVSS2: 4.3
EPSS Низкий

Описание

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libretro:retroarch:1.18.0:*:*:*:*:*:*:*
cpe:2.3:a:libretro:retroarch:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:libretro:retroarch:1.20.0:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00015
Низкий

5.3 Medium

CVSS3

7.8 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119
CWE-125

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component.

CVSS3: 5.3
debian
около 2 месяцев назад

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This ...

CVSS3: 5.3
github
около 2 месяцев назад

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 2%
0.00015
Низкий

5.3 Medium

CVSS3

7.8 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119
CWE-125