A heap buffer overflow vulnerability exists in stb_vorbis through 1.22, where the codebook multiplicands allocation size is truncated from size_t to int in the start_decoder() function. This can be exploited by crafting a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
CVE-2026-79516 is a Denial of Service (DoS) vulnerability in the stbsp_vsnprintf function of nothings stb commit 31c1ad3. The vulnerability allows attackers to cause a DoS via sending a crafted input. The CVSS score is 4, and the severity is MEDIUM. This vulnerability affects product deployments using nothings stb commit 31c1ad3. Defenders and developers should verify the affected versions and apply patch [truncated]
A critical integer overflow vulnerability exists in the stb_dupreplace function of Nothings stb image library, affecting versions up to commit f056911. The vulnerability can be triggered remotely through manipulation of the affected function, potentially leading to memory corruption or other undefined behavior. The stb library uses continuous delivery with rolling releases, meaning no traditional version [truncated]
A vulnerability in Nothings stb image library, specifically in the `stbhw_build_tileset_from_image` function, allows out-of-bounds read through manipulation of the `h_count` and `v_count` arguments. The vulnerability is remotely exploitable and affects versions up to commit f056911. The vendor uses a rolling release model and did not respond to disclosure attempts. The vulnerability was published on April [truncated]
A vulnerability in Nothings stb image library, specifically in the stbhw_build_tileset_from_image function of the Header Array Handler component, allows out-of-bounds read through manipulation of the width argument. The issue affects stb_image.h up to version 2.13 and can be exploited remotely. The vendor uses a rolling release model and did not respond to disclosure attempts.