在 GNOME 的图片查看器 Eye of GNOME(eog)中发现了一个漏洞。由于在解析分块元数据时状态处理不当,PNG 元数据读取器中存在堆缓冲区溢出漏洞。远程攻击者可以通过诱使用户打开精心构造的 PNG 文件来利用此漏洞,可能导致任意代码执行或因应用程序崩溃导致的拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89091 | 8.8 HIGH | Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows a |
| CVE-2026-93017 | 7.7 HIGH | Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and |
| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello: katello: katello flatpak remote repositories api cross-organizat |
| CVE-2026-107565 | 5.1 MEDIUM | Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat |
| CVE-2026-107604 | 4.9 MEDIUM | Keycloak-services: keycloak-services: view-clients role allows retrieval of active client |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization |
| CVE-2026-107623 | 4.3 MEDIUM | Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline |
No comments yet