CVE-2026-88384
OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-typ
CVSS
5.5
Medio
EPSS
0.2%
p8
KEV
—
Exploit Today
2
0-100
Publicado: 24 sept 2026 · Última mod.: 24 sept 2026 · CWE-476
Sin historial EPSS suficiente todavía.
OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL packed_data pointer. The OpaqueAttribute constructor passes the NULL pointer to memcpy() without validating the zero-size condition, resulting in undefined behavior and process termination, leading to denial of service.
- github.comhttps://github.com/AcademySoftwareFoundation/openexr/issues/2612
- github.comhttps://github.com/AcademySoftwareFoundation/openexr/pull/2615
- github.comhttps://github.com/AcademySoftwareFoundation/openexr/pull/2615/changes/70ddecfe82d2566f3776b8ed923939afd47baca2
- github.comhttps://github.com/AcademySoftwareFoundation/openexr/issues/2612
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-198887.5 ALT30.6%
——9Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required. Because PgBouncer serves all clients from a single process, this terminates every pooled connection.2dCVE-2026-428017.4 ALT9.6%
——3NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation.
This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.2dCVE-2026-883395.5 MED5.4%
——2A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.1dCVE-2026-843965.5 MED2.7%
——1InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.3dCVE-2026-761925.5 MED6.6%
——2InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.3dCVE-2026-860565.5 MED4.6%
——1Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members without checking for null. A process running at the same or a higher Windows integrity level on the same desktop can send NPPM_SAVESESSION with a null lParam, immediately terminating Notepad++ and causing denial of service and loss of unsaved documents. This issue is fixed in version 8.9.8.2d