CVE-2026-55893
- EPSS -
- Veröffentlicht 20.08.2026 21:32:46
- Zuletzt bearbeitet 20.08.2026 22:17:22
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-si...
CVE-2026-55894
- EPSS -
- Veröffentlicht 20.08.2026 21:31:37
- Zuletzt bearbeitet 20.08.2026 22:17:22
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] functi...
- EPSS 0.13%
- Veröffentlicht 14.08.2026 17:49:36
- Zuletzt bearbeitet 17.08.2026 20:16:43
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_ta...
CVE-2026-49282
- EPSS 0.13%
- Veröffentlicht 14.08.2026 17:44:44
- Zuletzt bearbeitet 17.08.2026 19:16:31
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instructi...
CVE-2026-47143
- EPSS 0.4%
- Veröffentlicht 21.07.2026 20:10:44
- Zuletzt bearbeitet 30.07.2026 15:16:57
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a ...
CVE-2025-68114
- EPSS 0.2%
- Veröffentlicht 17.12.2025 21:14:31
- Zuletzt bearbeitet 02.01.2026 18:33:09
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflo...
CVE-2025-67873
- EPSS 0.23%
- Veröffentlicht 17.12.2025 21:12:13
- Zuletzt bearbeitet 02.01.2026 18:39:54
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer...
CVE-2016-7151
- EPSS 0.98%
- Veröffentlicht 15.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 02:57:35
Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.
CVE-2017-6952
- EPSS 1.26%
- Veröffentlicht 16.03.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large v...