CVE-2026-9529
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.
CVSS
3.3
Bajo
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 26 may 2026 · Última mod.: 23 jul 2026 · CWE-404 · CWE-476
0.1%EPSS · 30 días0.1%
2026-06-302026-07-26
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.
- github.comhttps://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_oob_write_read_2004_compressed_section.dwg
- github.comhttps://github.com/LibreDWG/libredwg/issues/1247
- vuldb.comhttps://vuldb.com/submit/814273
- vuldb.comhttps://vuldb.com/vuln/365548
- vuldb.comhttps://vuldb.com/vuln/365548/cti
- www.gnu.orghttps://www.gnu.org/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-17574——
———HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.9hCVE-2026-175005.3 MED—
——0A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.8hCVE-2026-458167.5 ALT30.6%
——9NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.14hCVE-2026-500327.5 ALT18.0%
——5A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.4dCVE-2026-387635.5 MED7.4%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_138283dCVE-2026-130705.3 MED0.5%
——0A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.5d