VDB

GCVE-110-NCSC-2026-229

GCVE-110-NCSC-2026-229
Advisory PublishedCVSS 7.3/10
Vulnetix · Advisory published July 14, 2026
zlib versions 1.2 and later contain a denial of service vulnerability caused by a crafted compressed stream with an incomplete code description, resulting in a buffer overflow and application crash.

Weaknesses (CWE)

CWE-125Out-of-bounds ReadCWE-1335Incorrect Bitwise Shift of IntegerCWE-787Out-of-bounds WriteCWE-208Observable Timing DiscrepancyCWE-524Use of Cache Containing Sensitive InformationCWE-203Observable DiscrepancyCWE-294Authentication Bypass by Capture-replayCWE-122Heap-based Buffer OverflowCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-415Double FreeCWE-385Covert Timing ChannelCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-390Detection of Error Condition Without ActionCWE-863Incorrect AuthorizationCWE-426Untrusted Search PathCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-862Missing AuthorizationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-190Integer Overflow or WraparoundCWE-277Insecure Inherited PermissionsCWE-770Allocation of Resources Without Limits or ThrottlingCWE-347Improper Verification of Cryptographic Signature

Risk Scores

CVSS 3.1
7.3/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersionsPlatforms
Siemensvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

77,895 records in the GCVE database · Updated August 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›