CVE-2026-77396
— UNSCOREDpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame buffer whose capacity is derived from the declared media dimensions. A crafted AVI file can therefore cause an attacker-controlled out-of-bounds write past the heap allocation when an application plays the file or pulls its frames. The existing size assertion does not protect production release builds, where assertions are disabled. Typical local playback can crash the process, while applications that accept untrusted AVI sources expose a stronger memory-corruption condition. No fixed version is available as of this review.
Weaknesses
CWE-122, CWE-787
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-61714PoC
- HIGHCVE-2026-63422PoC
- HIGHCVE-2026-67549PoC
- CRITICALCVE-2016-15059PoC
- CRITICALCVE-2017-20241
- LOWCVE-2025-1218PoC
- HIGHCVE-2026-10027
- HIGHCVE-2026-100504PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.