CVEs (1,928)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode...Show more |
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based bu...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxAug 18, 2026 Jul 31, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxAug 18, 2026 Jul 31, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search agains...Show more |
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource...Show more |
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to...Show more |
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integer...Show more |
2Gnome Redhat2Enterprise Linux LibsoupAug 24, 2026 Jul 24, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destinati...Show more |
2Gnome Redhat2Enterprise Linux LibsoupAug 24, 2026 Jul 24, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and...Show more |
2Gnome Redhat2Enterprise Linux LibsoupAug 24, 2026 Jul 24, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit t...Show more |
2Gnome Redhat2Enterprise Linux LibsoupAug 24, 2026 Jul 21, 2026 N/A· v4 4.2 MEDIUM· v3 N/A· v2 A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated,...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshAug 17, 2026 Jul 21, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free c...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshAug 19, 2026 Jul 21, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server,...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 4, 2026 Jul 21, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without dete...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 3.9 LOW· v3 N/A· v2 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local de...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through rep...Show more |
2Libssh Redhat3Enterprise Linux Hardened ImagesLibsshSep 1, 2026 Jul 21, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. |