Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25758 | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .pcx file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability. |
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sail
Sail sail |
|
| CPEs | cpe:2.3:a:sail:sail:0.9.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Sail
Sail sail |
Mon, 25 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sail Software
Sail Software sail Image Decoding Library |
|
| Vendors & Products |
Sail Software
Sail Software sail Image Decoding Library |
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .pcx file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability. | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-11-03T18:09:24.987Z
Reserved: 2025-07-10T15:18:23.338Z
Link: CVE-2025-35984
Updated: 2025-11-03T18:09:24.987Z
Status : Modified
Published: 2025-08-25T15:15:39.080
Modified: 2025-11-03T19:15:52.450
Link: CVE-2025-35984
No data.
OpenCVE Enrichment
Updated: 2025-08-25T22:08:13Z
EUVD