CVE-2026-50310
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
CVSS
4.7
Medio
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 14 jul 2026 · Última mod.: 22 jul 2026 · CWE-190
0.3%EPSS · 30 días0.3%
2026-08-142026-09-10
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-870208.1 ALT—
———An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.10hCVE-2026-891467.5 ALT—
——0libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.14hCVE-2026-891586.5 MED—
——0PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.10hCVE-2026-891575.7 MED—
——0PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.9hCVE-2026-889144.4 MED—
——0A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.10hCVE-2026-16174——
——0Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.10h