发现 GIMP 中存在一个漏洞。在处理特制的 GIMPressionist 预设文件时,该插件在写入固定大小数组前未正确验证向量索引。这可能导致越界写入,从而破坏内存。攻击者可通过诱导用户加载恶意预设文件来利用此漏洞,可能引发程序崩溃或实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90959 | 8.1 HIGH | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl |
| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-95519 | 7.8 HIGH | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m |
| CVE-2026-94416 | 6.8 MEDIUM | Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery |
| CVE-2026-97177 | 6.6 MEDIUM | Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
| CVE-2026-97176 | 4.2 MEDIUM | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook |
No comments yet