CVE-2026-102805
- EPSS 0.35%
- Veröffentlicht 30.09.2026 00:15:17
- Zuletzt bearbeitet 01.10.2026 16:17:35
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer o...
CVE-2026-102804
- EPSS 0.35%
- Veröffentlicht 30.09.2026 00:00:17
- Zuletzt bearbeitet 02.10.2026 13:17:23
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer...
CVE-2026-79515
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 15:17:08
An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.
- EPSS 0.09%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 13:18:47
An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.
CVE-2026-18497
- EPSS 0.12%
- Veröffentlicht 07.08.2026 14:19:42
- Zuletzt bearbeitet 08.09.2026 14:07:24
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h l...
CVE-2026-5317
- EPSS 0.43%
- Veröffentlicht 02.04.2026 00:45:13
- Zuletzt bearbeitet 30.04.2026 20:28:59
A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released ...
CVE-2026-5316
- EPSS 0.44%
- Veröffentlicht 02.04.2026 00:00:18
- Zuletzt bearbeitet 30.04.2026 20:31:06
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is ...
CVE-2026-5315
- EPSS 0.51%
- Veröffentlicht 01.04.2026 23:15:12
- Zuletzt bearbeitet 30.04.2026 20:20:16
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can b...
CVE-2026-5314
- EPSS 0.66%
- Veröffentlicht 01.04.2026 22:15:15
- Zuletzt bearbeitet 30.04.2026 19:36:56
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of th...
CVE-2026-5313
- EPSS 0.29%
- Veröffentlicht 01.04.2026 21:30:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely....