QSearchQSearch

CVE-2025-3408

6.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911

Published: 2025-04-08 · Last updated: 2026-05-19

Severity and scoring

CVSS
6.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE
CWE-189, CWE-190

Affected products

VendorProduct
nothingsstb_image.h

Description

A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2025-3409 A vulnerability classified as critical has been found in Nothings stb up to f056911 (6.3 MEDIUM)
  • CVE-2025-3407 A vulnerability was found in Nothings stb up to f056911 (6.3 MEDIUM)
  • CVE-2025-3406 A vulnerability was found in Nothings stb up to f056911 (4.3 MEDIUM)

Same CWE

  • CVE-2026-10649 A flaw was found in Pacemaker (8.6 HIGH)
  • CVE-2026-53705 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good (7.6 HIGH)
  • CVE-2026-52722 A signed integer overflow vulnerability was found in GStreamer's VMnc decoder (7.1 HIGH)
  • CVE-2025-55647 An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of ... (5.5 MEDIUM)
  • CVE-2026-6045 LibreOffice can import EMF+ graphics, which may be embedded in documents