CVE-2026-105164Low· 2.7▾ SunlitA flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5475Medium· 5.5A vulnerability was determined in NASA cFS up to 7.0.0
CVE-2025-11494Low· 3.3A vulnerability was found in GNU Binutils 2.45
CVE-2026-101204Medium· 6.3A vulnerability was found in FastStone Image Viewer up to 8.3
CVE-2026-101205Medium· 6.3A vulnerability was determined in FastStone Image Viewer up to 8.3
CVE-2026-5476Medium· 4.6A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit
CVE-2025-15412Medium· 5.3A security vulnerability has been detected in WebAssembly wabt up to 1.0.39