Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end. An attacker-supplied image controls the overflowing bytes through its palette.
CVSS Score
6.3
EPSS Score
0.002
Published
2026-10-01
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.
CVSS Score
5.4
EPSS Score
0.002
Published
2026-10-01
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).
CVSS Score
6.5
EPSS Score
0.003
Published
2026-10-01
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.
CVSS Score
3.1
EPSS Score
0.003
Published
2026-10-01
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVSS Score
4.3
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVSS Score
5.4
EPSS Score
0.001
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVSS Score
5.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVSS Score
2.0
EPSS Score
0.003
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVSS Score
7.2
EPSS Score
0.004
Published
2026-10-01


Contact Us

Shodan ® - All rights reserved