CVE-2026-15041
- EPSS 0.3%
- Veröffentlicht 08.07.2026 10:15:30
- Zuletzt bearbeitet 09.07.2026 19:36:15
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurement...
CVE-2026-14969
- EPSS 0.08%
- Veröffentlicht 07.07.2026 15:48:04
- Zuletzt bearbeitet 09.07.2026 20:16:29
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across ...
CVE-2026-14940
- EPSS 0.31%
- Veröffentlicht 07.07.2026 13:54:20
- Zuletzt bearbeitet 09.07.2026 20:20:52
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the...
CVE-2026-11610
- EPSS 0.63%
- Veröffentlicht 07.07.2026 09:17:36
- Zuletzt bearbeitet 08.07.2026 21:16:46
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet t...
CVE-2026-58384
- EPSS 0.26%
- Veröffentlicht 07.07.2026 07:44:28
- Zuletzt bearbeitet 30.09.2026 15:22:31
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, po...
CVE-2026-59089
- EPSS 0.25%
- Veröffentlicht 06.07.2026 19:38:16
- Zuletzt bearbeitet 21.08.2026 12:16:29
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_clut...
CVE-2026-58380
- EPSS 0.26%
- Veröffentlicht 06.07.2026 13:58:43
- Zuletzt bearbeitet 30.09.2026 15:22:31
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundar...
CVE-2026-58381
- EPSS 0.12%
- Veröffentlicht 02.07.2026 19:45:33
- Zuletzt bearbeitet 22.09.2026 15:21:43
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial ...
CVE-2026-58010
- EPSS 0.39%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 06.10.2026 03:17:06
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of o...
CVE-2026-58011
- EPSS 0.38%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 06.10.2026 03:17:07
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corr...