Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 024

Количество 53 024

redhat логотип

CVE-2026-58494

26 дней назад

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-58472

27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-58471

27 дней назад

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-58470

27 дней назад

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-58469

27 дней назад

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-58467

около 1 месяца назад

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-58459

25 дней назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-58404

28 дней назад

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same addresses, including integer, hex, or octal, passed the policy. When a template passes an untrusted or data-derived URL to resources.GetRemote and the host platform uses the cgo system resolver, these encodings resolve to the blocked address, allowing build-time server-side requests to loopback and internal services, including the cloud-metadata endpoint in hosted or CI builds; the same check is reused on redirects, so the gap also applies to each redirect hop. This issue is fixed in v0.163.1.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2026-58403

28 дней назад

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regression caused RootMappingFs.statRoot to call Stat, which follows symlinks, instead of Lstat, so a direct os.ReadFile "somefile" where somefile was a symlink pointing outside the mount would return the target's contents. This effectively let a symlink planted inside a theme or local mount read arbitrary files reachable to the user running hugo. This issue is fixed in v0.163.1.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-58402

28 дней назад

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2026-58388

4 месяца назад

A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. A stack-based out-of-bounds write occurs in load_image() because a stack buffer sized as file_size - 0xE0 is later indexed using bounds based on file_size. This can corrupt stack memory and potentially lead to denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58387

4 месяца назад

A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image(), photo_date is allocated based on an unvalidated metadata separator offset and can become a 1-byte buffer before fread() writes the full metadata span into it. This could lead to heap memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58386

4 месяца назад

A flaw was found in GIMP's TIM loader. File-controlled width, height, and palette size values are used directly in multiple variable-length array declarations in load_image(), allowing a crafted TIM file to force oversized stack allocations and memory corruption. This could lead to denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58385

4 месяца назад

A flaw was found in GIMP's PVR decoder. A heap-based out-of-bounds write occurs in pvr_decode_compressed() because the Y-axis loop uses width / 2 instead of height / 2, allowing crafted non-square textures to write past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58384

4 месяца назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58383

4 месяца назад

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file sets bits-per-pixel to 0, causing the unpack loop to never advance and to write indefinitely past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58382

4 месяца назад

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file supplies an invalid bits-per-pixel value that causes the unpack loop to write beyond the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58381

4 месяца назад

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-58380

4 месяца назад

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-58379

4 месяца назад

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-58494

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

CVSS3: 6.5
0%
Низкий
26 дней назад
redhat логотип
CVE-2026-58472

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
0%
Низкий
27 дней назад
redhat логотип
CVE-2026-58471

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.

CVSS3: 5.9
0%
Низкий
27 дней назад
redhat логотип
CVE-2026-58470

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

CVSS3: 5.3
0%
Низкий
27 дней назад
redhat логотип
CVE-2026-58469

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

CVSS3: 6.5
0%
Низкий
27 дней назад
redhat логотип
CVE-2026-58467

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
25 дней назад
redhat логотип
CVE-2026-58404

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same addresses, including integer, hex, or octal, passed the policy. When a template passes an untrusted or data-derived URL to resources.GetRemote and the host platform uses the cgo system resolver, these encodings resolve to the blocked address, allowing build-time server-side requests to loopback and internal services, including the cloud-metadata endpoint in hosted or CI builds; the same check is reused on redirects, so the gap also applies to each redirect hop. This issue is fixed in v0.163.1.

CVSS3: 6.8
0%
Низкий
28 дней назад
redhat логотип
CVE-2026-58403

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regression caused RootMappingFs.statRoot to call Stat, which follows symlinks, instead of Lstat, so a direct os.ReadFile "somefile" where somefile was a symlink pointing outside the mount would return the target's contents. This effectively let a symlink planted inside a theme or local mount read arbitrary files reachable to the user running hugo. This issue is fixed in v0.163.1.

CVSS3: 6.5
0%
Низкий
28 дней назад
redhat логотип
CVE-2026-58402

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.

CVSS3: 5.4
0%
Низкий
28 дней назад
redhat логотип
CVE-2026-58388

A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. A stack-based out-of-bounds write occurs in load_image() because a stack buffer sized as file_size - 0xE0 is later indexed using bounds based on file_size. This can corrupt stack memory and potentially lead to denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58387

A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image(), photo_date is allocated based on an unvalidated metadata separator offset and can become a 1-byte buffer before fread() writes the full metadata span into it. This could lead to heap memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58386

A flaw was found in GIMP's TIM loader. File-controlled width, height, and palette size values are used directly in multiple variable-length array declarations in load_image(), allowing a crafted TIM file to force oversized stack allocations and memory corruption. This could lead to denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58385

A flaw was found in GIMP's PVR decoder. A heap-based out-of-bounds write occurs in pvr_decode_compressed() because the Y-axis loop uses width / 2 instead of height / 2, allowing crafted non-square textures to write past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58384

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-58383

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file sets bits-per-pixel to 0, causing the unpack loop to never advance and to write indefinitely past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58382

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file supplies an invalid bits-per-pixel value that causes the unpack loop to write beyond the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
4 месяца назад
redhat логотип
CVE-2026-58381

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-58380

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-58379

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу