CVE-2026-71222
- EPSS 0.11%
- Veröffentlicht 03.09.2026 12:23:22
- Zuletzt bearbeitet 22.09.2026 16:37:22
A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or caus...
- EPSS 0.14%
- Veröffentlicht 03.09.2026 12:23:17
- Zuletzt bearbeitet 22.09.2026 16:36:42
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution wh...
- EPSS 0.14%
- Veröffentlicht 03.09.2026 12:23:12
- Zuletzt bearbeitet 22.09.2026 16:31:31
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execut...
CVE-2026-71219
- EPSS 0.12%
- Veröffentlicht 03.09.2026 12:23:06
- Zuletzt bearbeitet 22.09.2026 16:26:18
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image ...
CVE-2026-82343
- EPSS 0.12%
- Veröffentlicht 28.08.2026 16:26:13
- Zuletzt bearbeitet 01.09.2026 15:17:31
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in b...
CVE-2026-82330
- EPSS 0.12%
- Veröffentlicht 28.08.2026 14:51:01
- Zuletzt bearbeitet 31.08.2026 22:14:22
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issu...
CVE-2026-82328
- EPSS 0.12%
- Veröffentlicht 28.08.2026 14:21:08
- Zuletzt bearbeitet 31.08.2026 22:15:16
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, re...
CVE-2026-82324
- EPSS 0.13%
- Veröffentlicht 28.08.2026 13:47:25
- Zuletzt bearbeitet 31.08.2026 22:19:24
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zer...
CVE-2026-5680
- EPSS 0.4%
- Veröffentlicht 27.08.2026 16:25:29
- Zuletzt bearbeitet 22.09.2026 16:17:49
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction....
CVE-2026-80101
- EPSS 0.15%
- Veröffentlicht 25.08.2026 20:36:47
- Zuletzt bearbeitet 02.09.2026 18:21:26
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the a...