CVE-2026-34235
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerabilit
CVSS
9.1
Critical
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Mar 31, 2026 · Last modified: Jul 24, 2026 · CWE-125
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability Structure (SS) data. Insufficient bounds checking on the payload descriptor length may cause reads beyond the allocated RTP payload buffer. This issue has been patched in version 2.17. A workaround for this issue involves disabling VP9 codec if not needed.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-965462.5 LOW—
——0A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.4hCVE-2026-965454.4 MED—
——0An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.4hCVE-2026-888405.3 MED—
——0BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.4hCVE-2026-888356.1 MED—
——0BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.4hCVE-2026-79616—4.6%
——1Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.8hCVE-2026-918176.1 MED4.8%
——1A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.6h