CVE-2026-103227
A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools
CVSS
6.3
Medio
EPSS
0.5%
p42
KEV
—
Exploit Today
13
0-100
Publicado: 30 sept 2026 · Última mod.: 2 oct 2026 · CWE-119 · CWE-120
0.5%EPSS · 30 días0.5%
2026-10-012026-10-04
A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.
- github.comhttps://github.com/gpac/gpac/
- github.comhttps://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd
- github.comhttps://github.com/gpac/gpac/issues/3876
- github.comhttps://github.com/gpac/gpac/pull/3879
- github.comhttps://github.com/gpac/gpac/releases/tag/abi-16.26
- vuldb.comhttps://vuldb.com/cve/CVE-2026-103227
- vuldb.comhttps://vuldb.com/submit/955033
- vuldb.comhttps://vuldb.com/vuln/411908
- vuldb.comhttps://vuldb.com/vuln/411908/cti
- github.comhttps://github.com/gpac/gpac/issues/3876
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1051642.7 BAJ—
——0A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.7hCVE-2026-88779—18.2%
KEV—55Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability8hCVE-2026-1046119.1 CRÍ40.2%
——12A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.3dCVE-2026-10461010.0 CRÍ49.1%
——15A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.3dCVE-2026-475507.8 ALT2.2%
——1NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.4dCVE-2026-81433—8.6%
——3A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.4d