CVE-2025-3408
6.3 MEDIUMA vulnerability was found in Nothings stb up to f056911
Published: 2025-04-08 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 6.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- CWE
- CWE-189, CWE-190
Affected products
| Vendor | Product |
|---|---|
| nothings | stb_image.h |
Description
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2025-3409 — A vulnerability classified as critical has been found in Nothings stb up to f056911 (6.3 MEDIUM)
- CVE-2025-3407 — A vulnerability was found in Nothings stb up to f056911 (6.3 MEDIUM)
- CVE-2025-3406 — A vulnerability was found in Nothings stb up to f056911 (4.3 MEDIUM)
Same CWE
- CVE-2026-10649 — A flaw was found in Pacemaker (8.6 HIGH)
- CVE-2026-53705 — A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good (7.6 HIGH)
- CVE-2026-52722 — A signed integer overflow vulnerability was found in GStreamer's VMnc decoder (7.1 HIGH)
- CVE-2025-55647 — An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of ... (5.5 MEDIUM)
- CVE-2026-6045 — LibreOffice can import EMF+ graphics, which may be embedded in documents