CVE-2026-7406
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A ma
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 ago 2026 · Última mod.: 6 ago 2026 · CWE-822
Sin historial EPSS suficiente todavía.
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-19023——
——0Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.5hCVE-2026-240837.8 ALT1.5%
——0Memory Corruption while processing IOCTL device driver requests with invalid arguments.9hCVE-2026-15029—3.4%
——1Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.
Refer to the '
Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.22dCVE-2026-483407.8 ALT6.7%
——2Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.21dCVE-2026-551385.5 MED27.1%
——8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.22dCVE-2026-551367.8 ALT22.6%
——7Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.22d