CVE-2026-47320
Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-824, CWE-674
- Published
- 2026-06-04
- Last modified
- 2026-06-08
Affected products
- Samsung Open Source rlottie
Weakness type
Related vulnerabilities
- CVE-2026-88054 — Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load
- CVE-2026-67281 — Unauthenticated file read in Mikrotik RouterOS
- CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize
- CVE-2026-47908 — Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-42959 — Crash during DNSSEC validation of malicious content
- CVE-2026-39458 — BIG-IP DNS Cache vulnerability
- CVE-2026-44411 — A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The...
- CVE-2026-6524 — Access of Uninitialized Pointer in Wireshark