Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90556

Опубликовано: 12 сент. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 дней назад

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

CVSS3: 7.8
debian
5 дней назад

Freeciv versions before 3.2.6 contain a heap buffer overflow in workli ...

CVSS3: 7.8
github
5 дней назад

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3

Дефекты

CWE-122