CVE-2024-2961
HIGH 7.3EPSS 88.3%
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
- CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H - EPSS
- 88.33% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-787
- Published
- 2024-04-17
- Updated
- 2026-07-14
Proof-of-concept exploits (14)
- 4wayhandshake/CVE-2024-29610★ · 2025-02-01
- ambionics/cnext-exploits504★ · 2024-09-30
- exfil0/test_iconv0★ · 2024-06-04
- jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento9★ · 2024-07-05
- kjdfklha/CVE-2024-2961_poc2★ · 2024-06-04
- kyotozx/CVE-2024-2961-Remote-File-Read5★ · 2025-05-07
- mesudmammad1/CVE-2023-26326_Buddyform_exploit0★ · 2025-02-12
- omarelshopky/exploit_cve-2023-26326_using_cve-2024-29611★ · 2025-02-02
- rvizx/CVE-2024-29615★ · 2024-05-20
- suce0155/CVE-2024-2961_buddyforms_2.7.74★ · 2025-02-04
- tnishiox/cve-2024-29610★ · 2024-06-04
- Clarissss/osTicketFileReadIntoRCE0★ · 2026-03-03
- suce0155/CVE-2024-2961
- horizon3ai/CVE-2026-2220012★ · 2026-01-22