在 GIMP 中发现了一个缺陷:在处理一个经过特殊构造的灯光预设文件时,光照效果滤镜未能正确验证光源数量。这可能导致越界写入,从而破坏内存。攻击者可以通过诱骗用户打开一个恶意的预设文件来利用此漏洞,进而可能导致程序崩溃,甚至实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90949 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis |
| CVE-2026-90948 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png |
| CVE-2026-90995 | 5.5 MEDIUM | Sssd: sssd: local denial of service due to null pointer dereference in pam responder |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90994 | 4.0 MEDIUM | Sssd: sssd: denial of service via malformed pam v1 requests |
| CVE-2026-90463 | 4.0 MEDIUM | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / ` |
No comments yet