5.5

CVSS3.1

CVE-2026-40915 - Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 5:28 p.m.

5

CVSS3.1

CVE-2026-40916 - Gimp: gimp: denial of service due to stack buffer overflow in tim image loader

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-len…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:29 p.m.

5

CVSS3.1

CVE-2026-40917 - Gimp: gimp: application crashes or information disclosure via crafted icns image files

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that proc…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:21 p.m.

5.5

CVSS3.1

CVE-2026-40918 - Gimp: gimp: denial of service via crafted pvr image file

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted P…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:23 p.m.

6.1

CVSS3.1

CVE-2026-40919 - Gimp: gimp: denial of service via specially crafted seattle filmworks file

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potenti…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:20 p.m.

7.3

CVSS3.1

CVE-2026-6384 - Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processi…

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:19 p.m.

5

CVSS3.1

CVE-2026-40256 - Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when …

πŸ“… Published: April 15, 2026, 6:36 p.m. πŸ”„ Last Modified: April 21, 2026, 2:02 p.m.

8.2

CVSS3.1

CVE-2026-34632 - Photoshop Installer | CWE-427: Uncontrolled Search Path Element

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the ap…

πŸ“… Published: April 15, 2026, 6:35 p.m. πŸ”„ Last Modified: April 22, 2026, 4:23 p.m.

4.1

CVSS3.1

CVE-2026-39845 - Weblate: SSRF via the webhook add-on using unprotected fetch_url()

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

πŸ“… Published: April 15, 2026, 6:26 p.m. πŸ”„ Last Modified: April 21, 2026, 2:05 p.m.

8.8

CVSS3.1

CVE-2026-34393 - Weblate: Privilege escalation in the user API endpoint

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:24 p.m. πŸ”„ Last Modified: April 21, 2026, 2:05 p.m.
Total resulsts: 347769
Page 297 of 34,777
Β« previous page Β» next page
Filters