CVE detail
CVE-2026-3707
A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipulation of the argument canvas_height leads to integer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 89771b201c66d15d29e4cc016d8aae82b6a5fbe1. It is advisable to implement a patch to correct this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/?submit.765972vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM - https://vuldb.com/?id.349653vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM - https://vuldb.com/?ctiid.349653vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM- https://github.com/MrNanko/webp4j/github.com
No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14787CVSS 1.9 · Low
A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handle…
- CVE-2026-14786CVSS 1.9 · Low
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer…
- CVE-2026-14761CVSS 1.9 · Low
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipula…
- CVE-2026-14758CVSS 1.9 · Low
A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexp…
- CVE-2026-14757CVSS 1.9 · Low
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer ove…
- CVE-2026-10722CVSS 1.9 · Low
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFrom…