CVE detail
CVE-2025-14958
A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library sokol_gfx.h. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 33e2271c431bf21de001e972f72da17a984da932. It is suggested to install a patch to address this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/?submit.717320vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 6:15 PM - https://vuldb.com/?id.337594vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 6:15 PM - https://vuldb.com/?ctiid.337594vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 6:15 PM No excerpt available.
Exploitgithub.comDec 19, 2025, 6:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 6:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 6:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 6:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- floooh/sokolHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 25, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-25583CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2026-25582CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2025-15537CVSS 1.9 · Low
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such m…
- CVE-2025-15536CVSS 1.9 · Low
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This ma…
- CVE-2026-0822CVSS 2.1 · Low
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based…
- CVE-2025-12204CVSS 1.9 · Low
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The man…