CVE-2026-14789
A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/for
CVSS
3.3
Bajo
EPSS
0.2%
p5
KEV
—
Exploit Today
1
0-100
Publicado: 6 jul 2026 · Última mod.: 9 jul 2026 · CWE-119 · CWE-121
0.1%EPSS · 30 días0.2%
2026-07-062026-07-21
A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to address this issue.
- github.comhttps://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762
- github.comhttps://github.com/radareorg/radare2/
- github.comhttps://github.com/radareorg/radare2/issues/26051
- vuldb.comhttps://vuldb.com/cve/CVE-2026-14789
- vuldb.comhttps://vuldb.com/submit/850389
- vuldb.comhttps://vuldb.com/vuln/376378
- vuldb.comhttps://vuldb.com/vuln/376378/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-16418——
——0Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)3hCVE-2026-59144——
——0Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq.
The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq does memcpy(out, ring_slot(h, seq), elem_size) with elem_size read raw from the mmap'd segment, copying into a fixed 8-byte destination scalar. An elem_size larger than 8 bytes writes past the destination.
A local peer that can write the backing file can leave the header valid while setting a large elem_size, so the next read copies a file-controlled length into the fixed 8-byte stack buffer, corrupting adjacent stack frames.6hCVE-2026-164129.8 CRÍ—
——0Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.6hCVE-2026-164119.8 CRÍ—
——0Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.6hCVE-2026-163619.8 CRÍ—
——0Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13.7hCVE-2026-163599.1 CRÍ—
——0Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.6h