MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can send crafted UDP packets to the configured UDPListen port to trigger an oversized memcpy operation that writes past the destination buffer, causing heap corruption and denial of service.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themoos
Themoos essential-moos |
|
| Vendors & Products |
Themoos
Themoos essential-moos |
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can send crafted UDP packets to the configured UDPListen port to trigger an oversized memcpy operation that writes past the destination buffer, causing heap corruption and denial of service. | |
| Title | MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length | |
| Weaknesses | CWE-191 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T22:38:28.519Z
Updated: 2026-09-04T13:40:51.952Z
Reserved: 2026-09-03T19:50:56.238Z
Link: CVE-2026-85436
Updated: 2026-09-04T13:28:26.260Z
Status : Awaiting Analysis
Published: 2026-09-03T23:17:22.937
Modified: 2026-09-08T20:07:17.943
Link: CVE-2026-85436
No data.