CVE-2026-10233
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos o
CVSS
3.3
Low
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026 · CWE-119 · CWE-125
0.1%EPSS · 30 days0.1%
2026-06-302026-07-23
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
- github.comhttps://github.com/assimp/assimp/
- github.comhttps://github.com/assimp/assimp/issues/6619
- github.comhttps://github.com/user-attachments/files/27228962/poc.zip
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10233
- vuldb.comhttps://vuldb.com/submit/821196
- vuldb.comhttps://vuldb.com/vuln/367512
- vuldb.comhttps://vuldb.com/vuln/367512/cti
- github.comhttps://github.com/assimp/assimp/issues/6619
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-659187.1 HIG—
———PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.8mCVE-2026-167685.3 MED—
———A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.10mCVE-2026-130777.1 HIG33.0%
——10A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a CodeWScope element, bypassing wire-level BSON validation. When the forged element is decompressed, the unchecked size value is used in pointer arithmetic, causing either a server crash or disclosure of adjacent heap memory contents.3hCVE-2026-648337.1 HIG33.4%
——10FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.22hCVE-2026-480297.1 HIG26.4%
——8libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.22hCVE-2026-164734.3 MED18.1%
——5A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.23h