Vulnerability Description
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/themoos/ui-moos
- https://github.com/themoos/ui-moos/blob/50b9c6c65169c501f746cfef1e167f74a7735e74
- https://github.com/themoos/ui-moos/commit/a6ebc0bc6cb360315ce620e865f996d189cddb
- https://github.com/themoos/ui-moos/pull/5
- https://www.vulncheck.com/advisories/moos-ui-moos-through-50b9c6c-ums-buffer-ove
FAQ
What is CVE-2026-85452?
CVE-2026-85452 is a vulnerability with a CVSS score of 8.8 (HIGH). MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf wit...
How severe is CVE-2026-85452?
CVE-2026-85452 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85452?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.