CVE-2026-92880
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder
CVSS
6.3
Medium
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Sep 17, 2026 · Last modified: Sep 17, 2026 · CWE-119 · CWE-787
Not enough EPSS history yet.
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.
- github.comhttps://github.com/vgmstream/vgmstream/
- github.comhttps://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024
- github.comhttps://github.com/vgmstream/vgmstream/issues/1994
- github.comhttps://github.com/vgmstream/vgmstream/pull/2008
- vuldb.comhttps://vuldb.com/cve/CVE-2026-92880
- vuldb.comhttps://vuldb.com/submit/942161
- vuldb.comhttps://vuldb.com/vuln/406346
- vuldb.comhttps://vuldb.com/vuln/406346/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-930156.3 MED15.9%
——5BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.1dCVE-2026-252807.8 HIG1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.2hCVE-2026-240747.8 HIG5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.2hCVE-2026-240737.8 HIG5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.2hCVE-2026-927867.8 HIG2.8%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.2dCVE-2026-203528.6 HIG34.4%
——10A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own.7h