snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
{
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39199.json",
"cna_assigner": "mitre"
}"2026-07-22T03:08:58Z"
[
{
"signature_type": "Line",
"target": {
"file": "memmap.cpp"
},
"deprecated": false,
"source": "https://github.com/snes9xgit/snes9x/commit/96b366100172723f6314c40e237b370f4f7b59f4",
"id": "CVE-2026-39199-4e002d1e",
"signature_version": "v1",
"digest": {
"line_hashes": [
"237793978649698808645407122816158080768",
"240650424735410410287698339852980331568",
"182004812249352264556856505651700875951",
"139049804054012269335212065855462569410"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "memmap.cpp",
"function": "ReadUPSPatch"
},
"deprecated": false,
"source": "https://github.com/snes9xgit/snes9x/commit/96b366100172723f6314c40e237b370f4f7b59f4",
"id": "CVE-2026-39199-6e21fe48",
"signature_version": "v1",
"digest": {
"function_hash": "150877881658155293726144271207618129571",
"length": 1735.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39199.json"