libvips是libvips开源的一个具有低内存需求的快速图像处理库。 libvips 8.19.0版本存在缓冲区错误漏洞,该漏洞源于对文件libvips/conversion/extract.c中函数vips_extract_band_build的参数extract_band的错误操作,可能导致越界读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | libvips | 8.19.0 |
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3292 | 6.3 MEDIUM | jizhiCMS Batch Model.php findAll sql injection |
| CVE-2026-3281 | 5.3 MEDIUM | libvips bandrank.c vips_bandrank_build heap-based overflow |
| CVE-2026-3284 | 3.3 LOW | libvips extract.c vips_extract_area_build integer overflow |
| CVE-2026-3282 | 3.3 LOW | libvips unpremultiply.c vips_unpremultiply_build out-of-bounds |
| CVE-2025-69437 | PublicCMS 安全漏洞 | |
| CVE-2026-26861 | CleverTap Web SDK 安全漏洞 | |
| CVE-2026-26862 | CleverTap Web SDK 安全漏洞 |
No comments yet