Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25738 | A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability. |
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sail
Sail sail |
|
| CPEs | cpe:2.3:a:sail:sail:0.9.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Sail
Sail sail |
Mon, 25 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sail Software
Sail Software sail Image Decoding Library |
|
| Vendors & Products |
Sail Software
Sail Software sail Image Decoding Library |
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability. | |
| Weaknesses | CWE-680 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-11-03T18:13:08.348Z
Reserved: 2025-07-10T15:38:10.397Z
Link: CVE-2025-52930
Updated: 2025-08-25T18:09:48.340Z
Status : Modified
Published: 2025-08-25T15:15:40.627
Modified: 2025-11-03T19:16:07.777
Link: CVE-2025-52930
No data.
OpenCVE Enrichment
Updated: 2025-08-25T22:08:10Z
EUVD