Stack-based Buffer Overflow in Nothings stb Product
CVE-2025-3409

5.3MEDIUM

Key Information:

Vendor

Nothings

Status
Vendor
CVE Published:
8 April 2025

What is CVE-2025-3409?

A stack-based buffer overflow vulnerability has been detected in the Nothings stb product, affecting the stb_include_string function. This issue arises when the argument path_to_includes is manipulated, potentially allowing for remote exploitation. Users are advised to be vigilant, as there is no versioning information available for this product, making it difficult to ascertain which releases are affected. Early disclosure attempts to the vendor went unanswered, raising concerns about the maintenance and support of this product.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

stb f056911

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ninpwn (VulDB User)
.