CVE-2026-8261
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. Thi
CVSS
5.9
Medium
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Published: May 11, 2026 · Last modified: Jul 23, 2026 · CWE-119 · CWE-122
0.2%EPSS · 30 days0.2%
2026-07-022026-07-30
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
- github.comhttps://github.com/albertodemichelis/squirrel/issues/326
- github.comhttps://github.com/biniamf/pocs/tree/main/squirrel-sqobject-functionproto-load-intovf-lineinfos
- vuldb.comhttps://vuldb.com/submit/809904
- vuldb.comhttps://vuldb.com/vuln/362558
- vuldb.comhttps://vuldb.com/vuln/362558/cti
- github.comhttps://github.com/albertodemichelis/squirrel/issues/326
- vuldb.comhttps://vuldb.com/submit/809904
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-54715——
——0GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.5hCVE-2026-179518.8 HIG9.2%
——3Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)1dCVE-2026-179358.8 HIG14.9%
——4Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)17hCVE-2026-177589.6 CRI13.3%
——4Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-176809.6 CRI23.5%
——7Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-133076.8 MED27.0%
——8Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of custom USB packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29048.1d