GNOME yelp是GNOME基金会开源的一个文档浏览工具。 GNOME yelp存在处理逻辑错误漏洞,该漏洞源于yelp-xsl提供的Content Security Policy实现过于宽松,可能导致恶意Flatpak应用程序通过OpenURI门户打开特制帮助内容,并通过在结构化SVG文档中嵌入不受信任的CSS样式表绕过沙箱隔离,允许Yelp评估本地XML包含并通过远程CSS资源请求泄露任意用户可读的主机文件,导致敏感信息未经授权泄露。以下版本受到影响:Red Hat Enterprise Linu
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 2:3.28.1-2.el7_9 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 2:3.28.1-3.el8_10.2 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 2:3.28.1-3.el8_4.2 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 2:3.28.1-3.el8_4.2 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 2:3.28.1-3.el8_6.2 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 2:3.28.1-3.el8_6.2 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 2:3.28.1-3.el8_8.2 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 2:3.28.1-3.el8_8.2 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 2:40.3-3.el9_8.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 2:40.3-2.el9_2.2 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 2:40.3-2.el9_4.2 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 2:40.3-2.el9_6.2 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12856 | 8.8 HIGH | Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the |
| CVE-2026-12912 | 7.3 HIGH | Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image |
| CVE-2026-13595 | 6.8 MEDIUM | Util-linux: util-linux: heap use-after-free in libblkid nested partition probing |
| CVE-2026-13757 | 6.2 MEDIUM | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing |
| CVE-2026-57965 | 5.1 MEDIUM | Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow |
| CVE-2026-57966 | 4.4 MEDIUM | Spice-vdagent: path traversal in file transfer via unsanitized filename |
No comments yet