CVE-2025-15536

Source
https://cve.org/CVERecord?id=CVE-2025-15536
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15536.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15536
Aliases
Downstream
Related
Published
2026-01-18T09:02:12.026Z
Modified
2026-07-22T03:36:16.490248Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
BYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow
Details

A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. Patch name: 345c9a50ab07018f1b4439776bad78a0d40778ec. To fix this issue, it is recommended to deploy a patch.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15536.json"
}
References

Affected packages

Git / github.com/byvoid/opencc

Affected ranges

Type
GIT
Repo
https://github.com/byvoid/opencc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:byvoid:open_chinese_convert:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.1.9"
        }
    ]
}

Affected versions

1.*
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
ver.*
ver.0.0.2
ver.0.0.3
ver.0.0.3.pre.1
ver.0.0.4
ver.0.0.5
ver.0.1.0
ver.0.1.1
ver.0.1.2
ver.0.4.0
ver.0.4.1
ver.0.4.2
ver.0.4.3
ver.1.0.1
ver.1.0.2
ver.1.0.3
ver.1.0.3-1
ver.1.0.4
ver.1.0.5
ver.1.0.6
ver.1.1.0
ver.1.1.1
ver.1.1.2
ver.1.1.3
ver.1.1.4
ver.1.1.5
ver.1.1.6
ver.1.1.7
ver.1.1.8
ver.1.1.9

Database specific

vanir_signatures_modified
"2026-07-22T03:36:16Z"
vanir_signatures
[
    {
        "target": {
            "file": "src/MaxMatchSegmentationTest.cpp"
        },
        "digest": {
            "line_hashes": [
                "70059274697442571074952561048178473278"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2025-15536-031172be",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    },
    {
        "target": {
            "function": "Conversion::Convert",
            "file": "src/Conversion.cpp"
        },
        "digest": {
            "length": 431.0,
            "function_hash": "6381518637341745790408454377949468909"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2025-15536-9ba516eb",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    },
    {
        "target": {
            "file": "src/MaxMatchSegmentation.cpp"
        },
        "digest": {
            "line_hashes": [
                "13155210609182758127440362113890544632",
                "262457899337220515738646061753602553158",
                "285213368059625420169449505333640788627",
                "7873400666696925498599951367764578229",
                "82056633348241842590845756684580931762",
                "175325883518381182824128990908566929299",
                "202880788568512139475792542587861056268",
                "183970471980939877521755136490344542285",
                "169186825631087214855367583253611868133",
                "256593017425488470075331074758697371507",
                "185456394026438316434147319624287037047",
                "271877632502434609502902958897391514026",
                "202041435387955471450439140463558346836"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2025-15536-c9b20953",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    },
    {
        "target": {
            "file": "src/Conversion.cpp"
        },
        "digest": {
            "line_hashes": [
                "35188034922160700419369850687172541047",
                "256813666568118900055544291833663595915",
                "121269006699948513830650119474442912441",
                "170553094775277015914406362643277452620",
                "309190718889097147965932571134085176669",
                "127036327170312509841037463510901863134",
                "110942305786751141037063811902824646986",
                "101266936448420575809005794680694800447",
                "231523677301811415958286139661605347437",
                "214552425441247126300055492671793234155",
                "238253398204744588669778591476607137300",
                "246553512758779271706903982662158257464"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2025-15536-d7aa7334",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    },
    {
        "target": {
            "file": "src/ConversionTest.cpp"
        },
        "digest": {
            "line_hashes": [
                "332063026749034846124606652766175785507"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2025-15536-e29b0e9c",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    },
    {
        "target": {
            "function": "MaxMatchSegmentation::Segment",
            "file": "src/MaxMatchSegmentation.cpp"
        },
        "digest": {
            "length": 757.0,
            "function_hash": "160052688247663851835510020033152236808"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2025-15536-fb68ecd1",
        "source": "https://github.com/byvoid/opencc/commit/345c9a50ab07018f1b4439776bad78a0d40778ec"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15536.json"