CVE-2026-20502High· 8.4▾ TwilightIn vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
mt2718_firmwaremt6580_firmwaremt6739_firmwaremt6761_firmwaremt6765_firmwaremt6768_firmwaremt6769_firmwaremt6779_firmwaremt6781_firmwaremt6785_firmwaremt6789_firmwaremt6833_firmwaremt6835_firmwaremt6853_firmwaremt6855_firmwaremt6858_firmwaremt6873_firmwaremt6877_firmwaremt6878_firmwaremt6879_firmwaremt6881_firmwaremt6883_firmwaremt6885_firmwaremt6886_firmwaremt6889_firmwaremt6893_firmwaremt6895_firmwaremt6897_firmwaremt6899_firmwaremt6983_firmwaremt6985_firmwaremt6989_firmwaremt6991_firmwaremt6993_firmwaremt8126_firmwaremt8171_firmwaremt8186_firmwaremt8188_firmwaremt8189_firmwaremt8195_firmwaremt8196_firmwaremt8367_firmwaremt8391_firmwaremt8395_firmwaremt8668_firmwaremt8676_firmwaremt8678_firmwaremt8696_firmwaremt8781_firmwaremt8788e_firmwaremt8792_firmwaremt8799_firmwaremt8910_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20501High· 8.4In vdec, there is a possible out of bounds write due to a heap buffer overflow
CVE-2026-20504Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
CVE-2026-20503Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
CVE-2026-20500Medium· 5.5In Modem, there is a possible system crash due to improper input validation
CVE-2026-25243High· 8.8Redis is an in-memory data structure store
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability