CVE-2026-56790
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.
CVSS
7.3
Alto
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 25 jun 2026 · Última mod.: 14 jul 2026 · CWE-193
0.2%EPSS · 30 días0.3%
2026-08-132026-09-10
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-over-IP to trigger an out-of-bounds array access and denial of service.
- github.comhttps://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f
- github.comhttps://github.com/canboat/canboat/issues/644
- github.comhttps://github.com/canboat/canboat/pull/649
- www.vulncheck.comhttps://www.vulncheck.com/advisories/canboat-off-by-one-global-buffer-overflow-in-searchforpgn
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-813967.8 ALT35.2%
——11Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2dCVE-2026-696095.5 MED33.1%
——10Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.3dCVE-2026-862978.1 ALT62.2%
——19A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.2dCVE-2026-81738—26.0%
——8OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries3dCVE-2026-57160—37.4%
——11PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.3dCVE-2026-174695.3 MED10.9%
——3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.2d