CVE-2026-16958
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CVSS
6.5
Medio
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 20 ago 2026 · Última mod.: 24 ago 2026 · CWE-787
0.4%EPSS · 30 días0.4%
2026-08-262026-09-23
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-888396.7 MED—
——0BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.5hCVE-2026-888327.3 ALT—
——0BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.5hCVE-2026-918157.8 ALT8.4%
——3Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.6hCVE-2026-918117.8 ALT6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.6hCVE-2026-918047.8 ALT6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.6hCVE-2026-918027.8 ALT6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.6h