CVE-2026-2239
- EPSS 0.49%
- Veröffentlicht 26.03.2026 20:00:28
- Zuletzt bearbeitet 03.04.2026 20:12:51
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly nu...
CVE-2026-2272
- EPSS 0.84%
- Veröffentlicht 26.03.2026 20:00:10
- Zuletzt bearbeitet 03.04.2026 20:17:54
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due ...
CVE-2026-2436
- EPSS 0.45%
- Veröffentlicht 26.03.2026 19:31:34
- Zuletzt bearbeitet 21.04.2026 15:48:48
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake co...
CVE-2026-4897
- EPSS 0.13%
- Veröffentlicht 26.03.2026 15:16:43
- Zuletzt bearbeitet 10.09.2026 18:18:01
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condit...
CVE-2026-4775
- EPSS 0.55%
- Veröffentlicht 24.03.2026 14:42:47
- Zuletzt bearbeitet 02.10.2026 02:17:02
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write du...
CVE-2026-1940
- EPSS 0.23%
- Veröffentlicht 23.03.2026 21:26:14
- Zuletzt bearbeitet 04.05.2026 15:30:08
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calcula...
CVE-2026-4647
- EPSS 0.17%
- Veröffentlicht 23.03.2026 13:37:44
- Zuletzt bearbeitet 01.09.2026 13:19:40
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not prop...
CVE-2026-4426
- EPSS 0.31%
- Veröffentlicht 19.03.2026 13:53:39
- Zuletzt bearbeitet 01.09.2026 13:19:39
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by suppl...
CVE-2026-4424
- EPSS 0.88%
- Veröffentlicht 19.03.2026 13:50:27
- Zuletzt bearbeitet 29.09.2026 01:16:51
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can expl...
CVE-2026-4271
- EPSS 0.83%
- Veröffentlicht 17.03.2026 11:14:21
- Zuletzt bearbeitet 19.05.2026 22:16:38
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause a...