在 GIMP 的 ICO 文件加载器中发现了一个缺陷。当处理包含嵌入式 PNG 图像的 ICO 文件时,在计算所需缓冲区大小的过程中可能会发生整数溢出。这会导致分配的缓冲区过小,当解码后的像素数据被写入时,就会引发基于堆的缓冲区溢出。远程攻击者可以通过构造一个恶意的 ICO 文件来利用此漏洞;当该文件被打开时,可能会导致任意代码执行或程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90947 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file |
| CVE-2026-90949 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mis |
| CVE-2026-90995 | 5.5 MEDIUM | Sssd: sssd: local denial of service due to null pointer dereference in pam responder |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90994 | 4.0 MEDIUM | Sssd: sssd: denial of service via malformed pam v1 requests |
| CVE-2026-90463 | 4.0 MEDIUM | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / ` |
No comments yet