CVE-2026-6384
- EPSS 0.01%
- Veröffentlicht 15.04.2026 19:09:10
- Zuletzt bearbeitet 28.04.2026 18:19:17
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial o...
CVE-2026-40919
- EPSS 0.02%
- Veröffentlicht 15.04.2026 18:59:16
- Zuletzt bearbeitet 28.04.2026 18:20:21
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service ...
CVE-2026-40918
- EPSS 0.02%
- Veröffentlicht 15.04.2026 18:59:14
- Zuletzt bearbeitet 28.04.2026 18:23:59
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the appli...
CVE-2026-40917
- EPSS 0.01%
- Veröffentlicht 15.04.2026 18:59:09
- Zuletzt bearbeitet 28.04.2026 18:21:27
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crash...
CVE-2026-40916
- EPSS 0%
- Veröffentlicht 15.04.2026 18:58:57
- Zuletzt bearbeitet 28.04.2026 18:29:38
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unco...
CVE-2026-40915
- EPSS 0.02%
- Veröffentlicht 15.04.2026 18:58:52
- Zuletzt bearbeitet 28.04.2026 17:28:06
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to ...
- EPSS 0.01%
- Veröffentlicht 09.04.2026 14:49:02
- Zuletzt bearbeitet 07.05.2026 22:16:36
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability upd...
CVE-2026-5745
- EPSS 0.02%
- Veröffentlicht 07.04.2026 14:57:31
- Zuletzt bearbeitet 03.05.2026 15:15:58
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without...
CVE-2026-5704
- EPSS 0.03%
- Veröffentlicht 06.04.2026 15:17:27
- Zuletzt bearbeitet 22.04.2026 20:08:59
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allo...
CVE-2026-5673
- EPSS 0.01%
- Veröffentlicht 06.04.2026 09:22:36
- Zuletzt bearbeitet 01.05.2026 19:53:02
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into op...