Количество 6
Количество 6
CVE-2026-87795
(zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)
CVE-2026-87795
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
CVE-2026-87795
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
CVE-2026-87795
zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...
GHSA-vc57-7frc-7vqx
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
BDU:2026-14471
Уязвимость компонента ZstdDictCompress библиотеки сжатия данных zstd-jni, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...) | CVSS3: 8.2 | 0% Низкий | 6 дней назад | |
CVE-2026-87795 zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes. | CVSS3: 8.2 | 0% Низкий | 7 дней назад | |
CVE-2026-87795 zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes. | CVSS3: 8.2 | 0% Низкий | 7 дней назад | |
CVE-2026-87795 zstd-jni versions before 1.5.7-14 fail to validate offset and length p ... | CVSS3: 8.2 | 0% Низкий | 7 дней назад | |
GHSA-vc57-7frc-7vqx zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes. | CVSS3: 8.2 | 0% Низкий | 7 дней назад | |
BDU:2026-14471 Уязвимость компонента ZstdDictCompress библиотеки сжатия данных zstd-jni, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.2 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу