CVE detail
CVE-2026-2889
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- https://vuldb.com/?submit.755029vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 10:15 PM - https://vuldb.com/?id.347182vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 10:15 PM - https://vuldb.com/?ctiid.347182vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 10:15 PM No excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PMNo excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PMNo excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PMNo excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PM- https://github.com/CCExtractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925github.com
No excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PM No excerpt available.
Exploitgithub.comFeb 21, 2026, 10:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19108CVSS 1.9 · Low
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mappin…
- CVE-2026-18785CVSS 1.9 · Low
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype…
- CVE-2026-43810CVSS 9.8 · Critical
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, vis…
- CVE-2026-16367CVSS 10.0 · Critical
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-15194CVSS 1.9 · Low
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation res…
- CVE-2026-14788CVSS 1.9 · Low
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such man…