CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file. |
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field. |
In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file. |
In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 31, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentiall...Show more |
It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted i...Show more |
A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input. |
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1 |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Aug 31, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unp...Show more |
4Debian DpdkFedoraproject+1 more8Data Plane Development Kit Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 31, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 31, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue a...Show more |
4Debian GnuRedhat+1 more4Debian Linux GzipJboss Data Grid+1 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arb...Show more |
3Asterisk DebianDigium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Aug 30, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port...Show more |
4Debian GnuMit+1 more4Debian Linux InetutilsKerberos 5+1 moreJun 17, 2026 Aug 30, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the te...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Aug 30, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections. |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 Aug 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash o...Show more |
3Debian LibtiffNetapp3Debian Linux LibtiffOntap Select Deploy Administration UtilityJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is av...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system. |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service. |