CVE-2024-14031
Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds
CVSS
8.1
Alto
EPSS
0.4%
p29
KEV
—
Exploit Today
9
0-100
Publicado: 31 mar 2026 · Última mod.: 25 jul 2026 · CWE-787
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-252807.8 ALT1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.21hCVE-2026-240747.8 ALT5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.21hCVE-2026-240737.8 ALT5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.21hCVE-2026-927867.8 ALT2.7%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.1dCVE-2026-91097—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-861075.9 MED28.6%
——9The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only.
A successful exploit can cause the affected process to terminate and restart, leading to a temporary disruption of traffic. Hosts on the internet that are unauthenticated and unable to form an overlay peer relationship can not trigger the vulnerable logic.1d