Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-47143

Опубликовано: 21 июл. 2026
Источник: nvd
CVSS3: 5.1
CVSS3: 5.9
EPSS Низкий

Описание

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in modRMRequired() and decode() when disassembling 3DNow! opcodes (0F 0F) in builds compiled with -DCAPSTONE_X86_REDUCE, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence 0F 0F <modrm> <imm8>. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:capstone-engine:capstone:*:*:*:*:*:*:*:*
Версия до 5.0.8 (исключая)
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha7:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00398
Низкий

5.1 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.1
ubuntu
14 дней назад

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

CVSS3: 5.9
redhat
14 дней назад

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

msrc
11 дней назад

Capstone has a NULL Pointer Dereference with 3DNow! opcodes

CVSS3: 5.1
debian
14 дней назад

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 an ...

EPSS

Процентиль: 33%
0.00398
Низкий

5.1 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-476