CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs Mar 27, 2026

CVE-2026-5037 | mxml up to 4.0.4 mxmlIndexNew mxml-index.c index_sort tempr stack-based overflow (Issue 350)

VulDB Archived Mar 27, 2026 ✓ Full text saved

A vulnerability classified as problematic was found in mxml up to 4.0.4 . This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew . Executing a manipulation of the argument tempr can lead to stack-based buffer overflow. This vulnerability is tracked as CVE-2026-5037 . The attack is restricted to local execution. Moreover, an exploit is present. A patch should be applied to remediate this issue.

Full text archived locally
✦ AI Summary · Claude Sonnet


    VDB-353963 · CVE-2026-5037 · ISSUE 350 MXML UP TO 4.0.4 MXMLINDEXNEW MXML-INDEX.C INDEX_SORT TEMPR STACK-BASED OVERFLOW HISTORYDIFFRELATEJSONXMLCTI CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score 3.0 $0-$5k 1.84+ Summaryinfo A vulnerability, which was classified as problematic, has been found in mxml up to 4.0.4. Impacted is the function index_sort of the file mxml-index.c of the component mxmlIndexNew. The manipulation of the argument tempr leads to stack-based overflow. This vulnerability is listed as CVE-2026-5037. The attack must be carried out locally. In addition, an exploit is available. To fix this issue, it is recommended to deploy a patch. Detailsinfo A vulnerability, which was classified as problematic, has been found in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. The manipulation of the argument tempr with an unknown input leads to a stack-based overflow vulnerability. Using CWE to declare the problem leads to CWE-121. A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). Impacted is availability. It is possible to read the advisory at github.com. The identification of this vulnerability is CVE-2026-5037. The exploitation is known to be easy. Attacking locally is a requirement. Technical details as well as a public exploit are known. The exploit is available at github.com. It is declared as proof-of-concept. Applying the patch 6e27354466092a1ac65601e01ce6708710bb9fa5 is able to eliminate this problem. The bugfix is ready for download at github.com. Productinfo Name mxml Version 4.0.0 4.0.1 4.0.2 4.0.3 4.0.4 License open-source CPE 2.3info 🔒 🔒 🔒 CPE 2.2info 🔒 🔒 🔒 CVSSv4info VulDB Vector: 🔒 VulDB Reliability: 🔍 CVSSv3info VulDB Meta Base Score: 3.3 VulDB Meta Temp Score: 3.0 VulDB Base Score: 3.3 VulDB Temp Score: 3.0 VulDB Vector: 🔒 VulDB Reliability: 🔍 CVSSv2info Vector Complexity Authentication Confidentiality Integrity Availability Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock VulDB Base Score: 🔒 VulDB Temp Score: 🔒 VulDB Reliability: 🔍 Exploitinginfo Class: Stack-based overflow CWE: CWE-121 / CWE-119 CAPEC: 🔒 ATT&CK: 🔒 Physical: Partially Local: Yes Remote: No Availability: 🔒 Access: Public Status: Proof-of-Concept Programming Language: 🔒 Download: 🔒 Price Prediction: 🔍 Current Price Estimation: 🔒 0-Day Unlock Unlock Unlock Unlock Today Unlock Unlock Unlock Unlock Threat Intelligenceinfo Interest: 🔍 Active Actors: 🔍 Active APT Groups: 🔍 Countermeasuresinfo Recommended: Patch Status: 🔍 0-Day Time: 🔒 Patch: 6e27354466092a1ac65601e01ce6708710bb9fa5 Timelineinfo 03/27/2026 Advisory disclosed 03/27/2026 +0 days VulDB entry created 03/27/2026 +0 days VulDB entry last update Sourcesinfo Advisory: 350 Status: Confirmed Confirmation: 🔒 CVE: CVE-2026-5037 (🔒) GCVE (CVE): GCVE-0-2026-5037 GCVE (VulDB): GCVE-100-353963 scip Labs: https://www.scip.ch/en/?labs.20161013 Entryinfo Created: 03/27/2026 17:28 Changes: 03/27/2026 17:28 (61) Complete: 🔍 Submitter: MTHG Cache ID: 99:DEA:101 Submitinfo Accepted Submit #778638: michaelrsweet mxml 4.0.4 Heap-based Buffer Overflow (by MTHG) Discussion No comments yet. Languages: en. Please log in to comment. ◂ PreviousOverviewNext ▸
    💬 Team Notes
    Article Info
    Source
    VulDB
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    Mar 27, 2026
    Archived
    Mar 27, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗