在3.3.1版本之前(2026年10月发布)的Canva Affinity应用程序,在解析Affinity文档文件中的文本时,未能正确处理不完整的UTF-8字符序列,从而导致堆缓冲区越界读取。攻击者可构造一个恶意的Affinity文档,当用户在Affinity中打开该文档时,可能会泄露文档文本相邻堆内存中的数据,或导致应用程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96396 | 4.9 MEDIUM | Affinity macOS < 3.3.1 整数溢出致堆缓冲区溢出 |
| CVE-2026-103220 | 4.5 MEDIUM | Affinity 3.3.1前版本图像解析越界读漏洞 |
| CVE-2026-96395 | 3.6 LOW | macOS Affinity <3.3.1 堆越界读取漏洞 |
| CVE-2026-96393 | 3.6 LOW | Affinity 3.3.1前越界指针解引用致崩溃 |
| CVE-2026-101130 | 3.6 LOW | Affinity 3.3.1前堆缓冲区越读漏洞 |
| CVE-2026-96394 | 2.9 LOW | Affinity for macOS <3.3.1 存在越界堆读取漏洞 |
No comments yet