CVE-2026-19550
- EPSS 0.19%
- Veröffentlicht 11.08.2026 20:46:42
- Zuletzt bearbeitet 28.09.2026 10:16:44
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Direc...
CVE-2026-59091
- EPSS 0.27%
- Veröffentlicht 10.08.2026 18:48:36
- Zuletzt bearbeitet 24.08.2026 20:16:50
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application beh...
CVE-2026-59090
- EPSS 0.55%
- Veröffentlicht 10.08.2026 12:10:40
- Zuletzt bearbeitet 30.09.2026 15:22:31
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an att...
CVE-2026-59088
- EPSS 0.26%
- Veröffentlicht 10.08.2026 10:53:03
- Zuletzt bearbeitet 21.08.2026 12:16:29
A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of ima...
CVE-2026-59087
- EPSS 0.37%
- Veröffentlicht 10.08.2026 10:47:07
- Zuletzt bearbeitet 24.08.2026 18:17:00
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could ...
CVE-2026-19404
- EPSS 0.42%
- Veröffentlicht 10.08.2026 09:38:10
- Zuletzt bearbeitet 14.08.2026 19:07:46
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access...
CVE-2026-42170
- EPSS 0.19%
- Veröffentlicht 08.08.2026 15:51:23
- Zuletzt bearbeitet 01.09.2026 14:25:12
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized hea...
CVE-2026-71227
- EPSS 0.13%
- Veröffentlicht 05.08.2026 12:42:10
- Zuletzt bearbeitet 21.09.2026 13:17:10
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-t...
CVE-2026-71226
- EPSS 0.13%
- Veröffentlicht 05.08.2026 12:37:17
- Zuletzt bearbeitet 21.09.2026 13:17:10
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
CVE-2026-71225
- EPSS 0.3%
- Veröffentlicht 05.08.2026 12:16:52
- Zuletzt bearbeitet 21.09.2026 13:17:09
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for ...