VDB
GCVE-110-NCSC-2026-229
GCVE-110-NCSC-2026-229
Advisory PublishedCVSS 7.3/10
zlib versions 1.2 and later contain a denial of service vulnerability caused by a crafted compressed stream with an incomplete code description, resulting in a buffer overflow and application crash.
Weaknesses (CWE)
CWE-125Out-of-bounds ReadCWE-1335Incorrect Bitwise Shift of IntegerCWE-787Out-of-bounds WriteCWE-208Observable Timing DiscrepancyCWE-524Use of Cache Containing Sensitive InformationCWE-203Observable DiscrepancyCWE-294Authentication Bypass by Capture-replayCWE-122Heap-based Buffer OverflowCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-415Double FreeCWE-385Covert Timing ChannelCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-390Detection of Error Condition Without ActionCWE-863Incorrect AuthorizationCWE-426Untrusted Search PathCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-862Missing AuthorizationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-190Integer Overflow or WraparoundCWE-277Insecure Inherited PermissionsCWE-770Allocation of Resources Without Limits or ThrottlingCWE-347Improper Verification of Cryptographic Signature
Risk Scores
CVSS 3.1
7.3/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Siemens | vers:unknown/* | — | — |
Aliases
CVE-2005-2096CVE-2016-9840CVE-2016-9841CVE-2016-9842CVE-2017-14919CVE-2018-25032CVE-2019-9494CVE-2019-9495CVE-2022-23303CVE-2022-23304CVE-2022-37434CVE-2022-37660CVE-2022-48174CVE-2023-45853CVE-2025-10585CVE-2025-13223CVE-2025-26465CVE-2025-32462CVE-2025-40945CVE-2025-5222CVE-2025-5914CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2026-0266CVE-2026-0272CVE-2026-0273CVE-2026-22184CVE-2026-5121CVE-2026-54429CVE-2026-56451CVE-2026-7891
References
Browse GCVE Records
77,895 records in the GCVE database · Updated August 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.