CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVSS
7.5
Alto
EPSS
51.7%
p99
KEV
—
Exploit Today
30
0-100
Publicado: 25 mar 2022 · Última mod.: 14 jul 2026 · CWE-787
51.7%EPSS · 30 días52.1%
2026-08-022026-08-30
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
- seclists.orghttp://seclists.org/fulldisclosure/2022/May/33
- seclists.orghttp://seclists.org/fulldisclosure/2022/May/35
- seclists.orghttp://seclists.org/fulldisclosure/2022/May/38
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/03/25/2
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/03/26/1
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- github.comhttps://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
- github.comhttps://github.com/madler/zlib/compare/v1.2.11...v1.2.12
- github.comhttps://github.com/madler/zlib/issues/605
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
- security.gentoo.orghttps://security.gentoo.org/glsa/202210-42
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20220526-0009/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-58106—2.7%
——1CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper.
At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size
passed down is the full PATH_MAX. safe_strcpy() is strncpy(), which NUL-pads the
destination out to the whole n, so this site writes 4096 bytes into the 4094 that remain — a
2-byte stack overflow on every invocation, independent of the input path's length.
This issue affects CodeChecker: through 6.28.2.2dCVE-2026-183935.4 MED16.8%
——5A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond
the bounds of a heap-allocated buffer when processing crafted TDSC cursor
data. A remote attacker could exploit this by supplying a specially crafted
video file, potentially leading to a denial of service or arbitrary code
execution.2dCVE-2026-78011—24.6%
——7An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.2dCVE-2026-78010—25.2%
——8A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.2dCVE-2026-78008—23.2%
——7A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.2dCVE-2026-19314—24.6%
——7An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.2d