Canva 公司的 Affinity 应用在 macOS 上,版本低于 3.3.1(2026年10月发布)时,在生成 Affinity 文档文件的 QuickLook 缩略图和预览时,未能安全地计算图像缓冲区的大小,从而导致整数溢出和基于堆的缓冲区溢出。恶意攻击者可构造一个特制的 Affinity 文档,当用户在访达(Finder)中查看或预览该文档时,可能导致堆内存被破坏,并使缩略图或预览扩展程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103220 | 4.5 MEDIUM | Affinity 3.3.1前版本图像解析越界读漏洞 |
| CVE-2026-101094 | 3.6 LOW | Affinity 3.3.1前堆缓冲区越界读取致内存泄露或崩溃 |
| CVE-2026-96395 | 3.6 LOW | macOS Affinity <3.3.1 堆越界读取漏洞 |
| CVE-2026-96393 | 3.6 LOW | Affinity 3.3.1前越界指针解引用致崩溃 |
| CVE-2026-101130 | 3.6 LOW | Affinity 3.3.1前堆缓冲区越读漏洞 |
| CVE-2026-96394 | 2.9 LOW | Affinity for macOS <3.3.1 存在越界堆读取漏洞 |
No comments yet