libvips是libvips开源的一个具有低内存需求的快速图像处理库。 libvips 8.19.0版本存在输入验证错误漏洞,该漏洞源于对文件libvips/conversion/extract.c中函数vips_extract_area_build的参数extract_area的错误操作,可能导致整数溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | libvips | 8.19.0 |
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3292 | 6.3 MEDIUM | jizhiCMS Batch Model.php findAll sql injection |
| CVE-2026-3281 | 5.3 MEDIUM | libvips bandrank.c vips_bandrank_build heap-based overflow |
| CVE-2026-3283 | 3.3 LOW | libvips extract.c vips_extract_band_build out-of-bounds |
| CVE-2026-3282 | 3.3 LOW | libvips unpremultiply.c vips_unpremultiply_build out-of-bounds |
| CVE-2025-69437 | PublicCMS 安全漏洞 | |
| CVE-2026-26861 | CleverTap Web SDK 安全漏洞 | |
| CVE-2026-26862 | CleverTap Web SDK 安全漏洞 |
No comments yet