VYPR

iconv

by FreeBSD

CVEs (2)

  • CVE-2026-58082Aug 19, 2026
    risk 0.00cvss epss

    The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application…

  • CVE-2026-58081Aug 19, 2026
    risk 0.00cvss epss

    Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be…