CVE-2026-26738 Details
Description
Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.
A buffer overflow vulnerability has been identified in Uderzo Software SpaceSniffer version 2.0.5.18. This vulnerability allows remote attackers to execute arbitrary code by exploiting a crafted .sns snapshot file. The issue arises because SpaceSniffer parses these files using an attacker-controlled length value, which is improperly validated, leading to stack-based memory corruption.
This vulnerability has been resolved in SpaceSniffer version 2.1.0.21.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.gruppotim.it/it/footer/red-team/2026/CVE-2026-26738-Uderzo-Software1.html | [email protected] | Third Party Advisory |
| https://www.gruppotim.it/it/footer/red-team/2026/CVE-2026-26738-UderzoSoftware.html | [email protected] | Broken Link |
| https://www.gruppotim.it/it/footer/red-team.html | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| uderzo spacesniffer | 2.0.5.18 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Mar 10, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | New CVE Received | [email protected] |