Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-54058

2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-54058

2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-54058

2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-54058

2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-62p4-gmf7-7g93

2 месяца назад

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

EPSS: Низкий
fstec логотип

BDU:2026-09900

3 месяца назад

Уязвимость функции PyImaging_MapBuffer() компонента src/map.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260831-80-0013

24 дня назад

Уязвимость python-pillow

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260831-73-0010

24 дня назад

Уязвимость python-pillow

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2026:48021

около 2 месяцев назад

Important: python-pillow security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48021

около 2 месяцев назад

ELSA-2026-48021: python-pillow security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21544-1

около 1 месяца назад

Security update for python-Pillow

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3084-1

2 месяца назад

Security update for python-Pillow

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3268-1

около 2 месяцев назад

Security update for python-Pillow

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

CVSS3: 9.1
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads ...

CVSS3: 9.1
1%
Низкий
2 месяца назад
github логотип
GHSA-62p4-gmf7-7g93

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-09900

Уязвимость функции PyImaging_MapBuffer() компонента src/map.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.1
1%
Низкий
3 месяца назад
redos логотип
ROS-20260831-80-0013

Уязвимость python-pillow

CVSS3: 9.1
1%
Низкий
24 дня назад
redos логотип
ROS-20260831-73-0010

Уязвимость python-pillow

CVSS3: 9.1
1%
Низкий
24 дня назад
rocky логотип
RLSA-2026:48021

Important: python-pillow security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-48021

ELSA-2026-48021: python-pillow security update (IMPORTANT)

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21544-1

Security update for python-Pillow

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3084-1

Security update for python-Pillow

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3268-1

Security update for python-Pillow

около 2 месяцев назад

Уязвимостей на страницу