gdk-pixbuf 中存在一个缺陷。该漏洞允许远程攻击者通过提供一个精心构造的 Apple 图标图像(.icns)文件,导致堆栈越界读取(heap out-of-bounds read)。负责处理 RLE 编码 ICNS 图标数据的 uncompress() 函数在解压过程中未对源缓冲区边界进行有效验证。此问题可能导致拒绝服务(DoS),表现为应用程序崩溃;也可能导致信息泄露,可能会从相邻内存中暴露敏感数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78234 | 9.9 CRITICAL | Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificat |
| CVE-2026-80219 | 8.7 HIGH | Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret |
| CVE-2026-74860 | 8.5 HIGH | Libxml2: double-free/uaf in libxml2 python bindings |
| CVE-2026-77968 | 8.2 HIGH | Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serv |
| CVE-2026-76561 | 7.2 HIGH | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile con |
| CVE-2026-74859 | 6.8 MEDIUM | Gnome-tweaks: path traversal in theme installer |
| CVE-2026-86564 | 3.3 LOW | Dpdk: dpdk: missing length validation before reading command_data in virtio-net control qu |
No comments yet