CVE detail
CVE-2026-34253
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34253.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 15, 2026, 3:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2477925bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 15, 2026, 3:16 PM - https://access.redhat.com/security/cve/CVE-2026-34253access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 3:16 PM - https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332gitlab.xiph.org
No excerpt available.
referencegitlab.xiph.orgMay 15, 2026, 3:16 PM No excerpt available.
Exploitgithub.comMay 15, 2026, 3:16 PMNo excerpt available.
Exploitgithub.comMay 15, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16439CVSS 5.8 · Medium
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
- CVE-2026-26199CVSS 5.9 · Medium
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter,…
- CVE-2026-44631CVSS 9.8 · Critical
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. User…
- CVE-2024-36343CVSS 4.6 · Medium
Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited sectio…
- CVE-2026-5089CVSS 7.3 · High
YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#…
- CVE-2026-41499CVSS 6.5 · Medium
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE…