MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themoos
Themoos ui-moos |
|
| Vendors & Products |
Themoos
Themoos ui-moos |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution. | |
| Title | MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers | |
| Weaknesses | CWE-787 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T22:38:39.695Z
Updated: 2026-09-04T18:29:59.933Z
Reserved: 2026-09-03T19:51:02.000Z
Link: CVE-2026-85452
Updated: 2026-09-04T18:29:54.897Z
Status : Awaiting Analysis
Published: 2026-09-03T23:17:25.330
Modified: 2026-09-08T20:07:17.943
Link: CVE-2026-85452
No data.