Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1485

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 2.8
EPSS Низкий

Описание

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

EPSS

Процентиль: 2%
0.00013
Низкий

2.8 Low

CVSS3

Дефекты

CWE-124

Связанные уязвимости

CVSS3: 2.8
ubuntu
11 дней назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
debian
11 дней назад

A flaw was found in Glib's content type parsing logic. This buffer und ...

CVSS3: 2.8
github
11 дней назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

suse-cvrf
3 дня назад

Security update for glib2

suse-cvrf
3 дня назад

Security update for glib2

EPSS

Процентиль: 2%
0.00013
Низкий

2.8 Low

CVSS3

Дефекты

CWE-124