Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 08 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipulation of the argument canvas_height leads to integer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 89771b201c66d15d29e4cc016d8aae82b6a5fbe1. It is advisable to implement a patch to correct this issue. | |
| Title | MrNanko webp4j gif_decoder.c DecodeGifFromMemory integer overflow | |
| Weaknesses | CWE-189 CWE-190 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-08T05:02:15.404Z
Reserved: 2026-03-07T09:09:50.930Z
Link: CVE-2026-3707
No data.
Status : Received
Published: 2026-03-08T05:16:32.193
Modified: 2026-03-08T05:16:32.193
Link: CVE-2026-3707
No data.
OpenCVE Enrichment
No data.