Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory. | |
| Title | ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response | |
| First Time appeared |
Zoneminder
Zoneminder zoneminder |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zoneminder
Zoneminder zoneminder |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:28:08.065Z
Reserved: 2026-09-28T21:24:39.616Z
Link: CVE-2026-102296
No data.
Status : Received
Published: 2026-09-28T22:17:32.233
Modified: 2026-09-28T22:17:32.233
Link: CVE-2026-102296
No data.
OpenCVE Enrichment
No data.
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')