A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Sun, 01 Mar 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | FascinatedBox lily lily_emitter.c clear_storages out-of-bounds | |
| Weaknesses | CWE-119 CWE-125 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-01T11:32:08.714Z
Updated: 2026-03-01T11:32:08.714Z
Reserved: 2026-02-28T17:03:49.590Z
Link: CVE-2026-3391
No data.
Status : Received
Published: 2026-03-01T12:15:59.180
Modified: 2026-03-01T12:15:59.180
Link: CVE-2026-3391
No data.
ReportizFlow