libvips 8.19.0 在处理小端序 PFM(Portable Float Map)图像时存在内存访问漏洞。如果 PFM 文件文本头部的长度不是 4 字节的整数倍,基于 mmap 的加载器可能会将像素数据暴露在未针对浮点数访问进行正确对齐的内存地址上。随后, 函数通过浮点指针对该缓冲区进行解引用操作,从而引发未定义行为。在严格对齐要求的架构上或在启用 UBSan(Undefined Behavior Sanitizer)的检测构建中,这会导致程序终止,进而引发拒绝服务(DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97225 | 6.3 MEDIUM | DbGate JSON Runner runners.js code injection |
| CVE-2026-96884 | 6.3 MEDIUM | MantisZip Preview MainWindow.UI.cs Path.Combine path traversal |
| CVE-2026-97226 | 6.3 MEDIUM | DbGate files-style Endpoint files.js fs.readFile path traversal |
| CVE-2026-97224 | 4.3 MEDIUM | Excalidraw Imported File restore.ts cross site scripting |
| CVE-2026-97179 | 4.3 MEDIUM | O2OA Cipher Connection CipherConnectionAction.java list information disclosure |
| CVE-2026-88368 | NanoSVG 坐标解析整数溢出致DoS | |
| CVE-2026-51996 | geelen mcp-remote任意代码执行漏洞 | |
| CVE-2026-88372 | libsndfile 1.2.2 MAT4文件解析整数溢出漏洞 | |
| CVE-2026-88373 | libde265空指针解引用致拒绝服务漏洞 | |
| CVE-2026-88388 | Espruino 2v29栈溢出漏洞 | |
| CVE-2026-88370 | libconfini 1.16.4堆溢出漏洞 | |
| CVE-2026-88358 | simdjson 4.6.1堆越界读取导致拒绝服务 | |
| CVE-2026-88351 | MPack 1.1.1 堆缓冲区溢出漏洞 | |
| CVE-2026-88369 | jsmn示例jsondump.c缓冲区溢出漏洞 | |
| CVE-2026-88377 | Bento4 1.6.0.0 AVC/HVC解析整数下溢导致DoS | |
| CVE-2026-88357 | nDPI 5.1.0 DNS解析漏洞致拒绝服务 | |
| CVE-2026-88371 | ZBar Code 128解析漏洞致拒绝服务 | |
| CVE-2026-88361 | SumatraPDF 3.6.1 PDF页码标签整数溢出漏洞 | |
| CVE-2026-51997 | mcp-remote 0.1.16-0.1.38 远程代码执行漏洞 | |
| CVE-2026-51995 | mcp-remote 0.1.32-0.1.38 信息泄露漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet