CVE-2026-6384
- EPSS 0.26%
- Veröffentlicht 15.04.2026 19:09:10
- Zuletzt bearbeitet 30.09.2026 19:16:41
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial o...
CVE-2026-40919
- EPSS 0.33%
- Veröffentlicht 15.04.2026 18:59:16
- Zuletzt bearbeitet 28.04.2026 18:20:21
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service ...
CVE-2026-40918
- EPSS 0.2%
- Veröffentlicht 15.04.2026 18:59:14
- Zuletzt bearbeitet 28.04.2026 18:23:59
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the appli...
CVE-2026-40917
- EPSS 0.17%
- Veröffentlicht 15.04.2026 18:59:09
- Zuletzt bearbeitet 28.04.2026 18:21:27
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crash...
CVE-2026-40916
- EPSS 0.21%
- Veröffentlicht 15.04.2026 18:58:57
- Zuletzt bearbeitet 28.04.2026 18:29:38
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unco...
CVE-2026-40915
- EPSS 0.38%
- Veröffentlicht 15.04.2026 18:58:52
- Zuletzt bearbeitet 28.04.2026 17:28:06
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to ...
CVE-2026-6245
- EPSS 0.14%
- Veröffentlicht 15.04.2026 18:35:19
- Zuletzt bearbeitet 01.09.2026 12:17:43
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C str...
CVE-2026-34486
- EPSS 82.93%
- Veröffentlicht 09.04.2026 20:16:25
- Zuletzt bearbeitet 21.09.2026 19:17:04
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to ve...
- EPSS 0.21%
- Veröffentlicht 09.04.2026 14:49:02
- Zuletzt bearbeitet 09.10.2026 23:16:54
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability upd...
CVE-2026-5745
- EPSS 0.16%
- Veröffentlicht 07.04.2026 14:57:31
- Zuletzt bearbeitet 01.09.2026 12:17:43
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without...