CVE detail
CVE-2025-15536
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. Patch name: 345c9a50ab07018f1b4439776bad78a0d40778ec. To fix this issue, it is recommended to deploy a patch.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/?submit.733347vuldb.com
No excerpt available.
Exploitvuldb.comJan 18, 2026, 9:15 AM - https://vuldb.com/?id.341708vuldb.com
No excerpt available.
Exploitvuldb.comJan 18, 2026, 9:15 AM - https://vuldb.com/?ctiid.341708vuldb.com
No excerpt available.
Exploitvuldb.comJan 18, 2026, 9:15 AM No excerpt available.
Exploitgithub.comJan 18, 2026, 9:15 AMNo excerpt available.
Exploitgithub.comJan 18, 2026, 9:15 AMNo excerpt available.
Exploitgithub.comJan 18, 2026, 9:15 AMNo excerpt available.
Exploitgithub.comJan 18, 2026, 9:15 AM- https://github.com/BYVoid/OpenCC/github.com
No excerpt available.
Exploitgithub.comJan 18, 2026, 9:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- BYVoid/OpenCCHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 26, 2026, 12:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-25583CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2026-25582CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2025-15537CVSS 1.9 · Low
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such m…
- CVE-2026-0822CVSS 2.1 · Low
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based…
- CVE-2025-14958CVSS 1.9 · Low
A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library…
- CVE-2025-12204CVSS 1.9 · Low
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The man…