MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themoos
Themoos core-moos |
|
| Vendors & Products |
Themoos
Themoos core-moos |
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process. | |
| Title | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length | |
| Weaknesses | CWE-195 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T22:38:31.884Z
Updated: 2026-09-04T13:40:46.393Z
Reserved: 2026-09-03T19:50:58.148Z
Link: CVE-2026-85441
Updated: 2026-09-04T13:28:28.168Z
Status : Awaiting Analysis
Published: 2026-09-03T23:17:23.740
Modified: 2026-09-08T20:07:17.943
Link: CVE-2026-85441
No data.