CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 17 sept 2026 · Última mod.: 17 sept 2026 · CWE-787
Sin historial EPSS suficiente todavía.
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-252807.8 ALT—
———Memory corruption when processing escape handling flow with insufficient user buffer sizes.7hCVE-2026-240747.8 ALT—
———Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.7hCVE-2026-927867.8 ALT—
———LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.15hCVE-2026-91097——
———HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.17hCVE-2026-861075.9 MED—
———The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only.
A successful exploit can cause the affected process to terminate and restart, leading to a temporary disruption of traffic. Hosts on the internet that are unauthenticated and unable to form an overlay peer relationship can not trigger the vulnerable logic.17hCVE-2026-917118.8 ALT—
———Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8h