<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Google Pixel (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/pixel.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/pixel-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Google Pixel (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46599 – The TIFF decoder does not place a limit on the size of PackBits-compressed data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46599</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46599</strong></p>
  <p>The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46209 – In the Linux kernel, the following vulnerability has been resolved:

drm/gem: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46209</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46209</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()  drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions using plain integer division:    unsigned int width  = mode_cmd->width  / (i ? info->hsub : 1);   unsigned int height = mode_cmd->height / (i ? info->vsub : 1);  However, the i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44988 – LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44988</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44988</strong></p>
  <p>LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight rectangles whose width is larger than 2048 pixels. A malicious VNC server can send a crafted FramebufferUpdate rectangle using Tight encoding with NoZlib | ExplicitFilter and…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32741 – libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32741</guid>
    <pubDate>Tue, 19 May 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32741</strong></p>
  <p>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32740 – libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32740</guid>
    <pubDate>Tue, 19 May 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32740</strong></p>
  <p>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal imag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44636 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44636</guid>
    <pubDate>Thu, 14 May 2026 20:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44636</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From  to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no upper bound. width and height are multiplied as plain int when computing the allo…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43908 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43908</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43908</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a large negative pointer offset into the output buffer, producing an out-of-bounds write that crashes th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43907 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43907</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43907</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a heap-based out-of-bounds write when processing crafted DPX image files. The function computes buffer sizes using 32-bit signed integer arithmet…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43905 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43905</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43905</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes buffer size as const int bufsize = w * h * ch * buffer_bpp using signed 32-bit arithmetic. When the product exceeds INT_MAX, the result wraps to 0 or a small value. m_buf.resize() allocates an undersized bu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7049 – The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7049</guid>
    <pubDate>Sat, 02 May 2026 06:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7049</strong></p>
  <p>The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The S…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41309 – Open Source Social Network (OSSN) is open-source social networking software deve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41309</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41309</strong></p>
  <p>Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be small, the server attempts to allocate significant memory and CPU cycles during th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40493 – SAIL is a cross-platform library for loading and saving images with support for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40493</guid>
    <pubDate>Sat, 18 Apr 2026 03:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40493</strong></p>
  <p>SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes bytes-per-pixel (`bpp`) from raw header fields `channels * depth`, but the pixel buffer is allocated based on the resolved pixel format. For LAB mode with `channels=3, depth=16`, `bpp = (3*16+7)/8 =…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40492 – SAIL is a cross-platform library for loading and saving images with support for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40492</guid>
    <pubDate>Sat, 18 Apr 2026 03:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40492</strong></p>
  <p>SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves pixel format based on `pixmap_depth` but the byte-swap code uses `bits_per_pixel` independently. When `pixmap_depth=8` (BPP8_INDEXED, 1 byte/pixel buffer) but `bits_per_pixel=32`, the byte-swap loop…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33021 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33021</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33021</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a defensive copy. When a resize operation is triggered, sixel_frame_convert_to_rgb888() unconditionally frees t…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33020 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33020</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33020</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel co…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33018 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33018</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33018</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and reallocates frame->pixels between frames without consulting the object's reference c…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5445 – An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5445</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5445</strong></p>
  <p>An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used for `PALETTE COLOR` images does not validate pixel indices against the lookup table size. Crafted images containing indices larger than the palette size cause the decoder to read beyond allocated lookup table memory and expose heap contents in the out…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5444 – A heap buffer overflow vulnerability exists in the PAM image parsing logic. When...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5444</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5444</strong></p>
  <p>A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen values can cause an integer overflow during buffer size calculation, resulting in the allocation of a small buffer followed by a much larger write operation during pixel p…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5443 – A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5443</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5443</strong></p>
  <p>A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35444 – SDL_image is a library to load images of various formats as SDL surfaces. In do_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35444</guid>
    <pubDate>Mon, 06 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35444</strong></p>
  <p>SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34545 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34545</guid>
    <pubDate>Wed, 01 Apr 2026 21:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34545</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primit…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34543 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34543</guid>
    <pubDate>Wed, 01 Apr 2026 21:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34543</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33984 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33984</guid>
    <pubDate>Mon, 30 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33984</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33636 – LIBPNG is a reference library for use in applications that read, create, and man...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33636</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33636</strong></p>
  <p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that en…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32545 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32545</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32545</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Taboola Taboola Pixel taboola-pixel allows Reflected XSS.This issue affects Taboola Pixel: from n/a through <= 1.1.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31806 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31806</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31806</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0,  the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27622 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27622</guid>
    <pubDate>Tue, 03 Mar 2026 23:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27622</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32.  overall_sample_count is then derived from wrapped tota…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26965 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26965</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26965</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verifying that `(nYDst+nSrcHeight)` fits in the destination height or that `(nXDst+nSrcWidth)` fits in the destination stride. When `TempFormat != DstFormat`, `pDst…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26955 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26955</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26955</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to vali…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25794 – ImageMagick is free and open-source software used for editing and manipulating d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25794</guid>
    <pubDate>Tue, 24 Feb 2026 01:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25794</strong></p>
  <p>ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or poten…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27072 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27072</guid>
    <pubDate>Fri, 20 Feb 2026 16:22:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27072</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager pixelyoursite allows Stored XSS.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through <= 11.2.0.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1841 – The PixelYourSite – Your smart PIXEL (TAG) &amp; API Manager plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1841</guid>
    <pubDate>Fri, 13 Feb 2026 22:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1841</strong></p>
  <p>The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1837 – A specially-crafted file can cause libjxl's decoder to write pixel data to unini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1837</guid>
    <pubDate>Wed, 11 Feb 2026 16:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1837</strong></p>
  <p>A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data.  This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66909 – Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66909</guid>
    <pubDate>Fri, 19 Dec 2025 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66909</strong></p>
  <p>Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java loads images using OpenCV's imread() function without validating dimensions or pixel count before decompression. An attacker can upload a specially crafted compressed image file (e.g., PNG) that is small…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53619 – An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53619</guid>
    <pubDate>Tue, 16 Dec 2025 22:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53619</strong></p>
  <p>An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `null_convert` is called based of the value of the malicious DICOM file specifying the intended interpretation of the image pixel data</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53618 – An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53618</guid>
    <pubDate>Tue, 16 Dec 2025 22:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53618</strong></p>
  <p>An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `grayscale_convert` is called based of the value of the malicious DICOM file specifying the intended interpretation of the image pixe…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59733 – When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59733</guid>
    <pubDate>Mon, 06 Oct 2025 08:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59733</strong></p>
  <p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are "B", "G", "R" and "A". The channel parsing code can be found in decode_header. The buffer td->uncompressed_data is allocated in decode_block based on the xsize, ysize and computed curre…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36904 – WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36904</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36904</strong></p>
  <p>WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36901 – WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36901</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36901</strong></p>
  <p>WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36896 – WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36896</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36896</strong></p>
  <p>WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31914 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31914</guid>
    <pubDate>Fri, 23 May 2025 13:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31914</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Blind SQL Injection.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.2.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23679 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23679</guid>
    <pubDate>Wed, 22 Jan 2025 15:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23679</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flourish Pixel FP RSS Category Excluder fp-rss-category-excluder allows Reflected XSS.This issue affects FP RSS Category Excluder: from n/a through <= 1.0.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47031 – Android before 2024-10-05 on Google Pixel devices allows privilege escalation in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47031</guid>
    <pubDate>Fri, 25 Oct 2024 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47031</strong></p>
  <p>Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47022 – Android before 2024-10-05 on Google Pixel devices allows information disclosure ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47022</guid>
    <pubDate>Fri, 25 Oct 2024 11:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47022</strong></p>
  <p>Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47020 – Android before 2024-10-05 on Google Pixel devices allows information disclosure ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47020</guid>
    <pubDate>Fri, 25 Oct 2024 11:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47020</strong></p>
  <p>Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47014 – Android before 2024-10-05 on Google Pixel devices allows privilege escalation in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47014</guid>
    <pubDate>Fri, 25 Oct 2024 11:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47014</strong></p>
  <p>Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44100 – Android before 2024-10-05 on Google Pixel devices allows information disclosure ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44100</guid>
    <pubDate>Fri, 25 Oct 2024 11:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44100</strong></p>
  <p>Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32929 – In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32929</guid>
    <pubDate>Thu, 13 Jun 2024 21:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32929</strong></p>
  <p>In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32922 – In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32922</guid>
    <pubDate>Thu, 13 Jun 2024 21:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32922</strong></p>
  <p>In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32899 – In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible comprom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32899</guid>
    <pubDate>Thu, 13 Jun 2024 21:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32899</strong></p>
  <p>In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47383 – In the Linux kernel, the following vulnerability has been resolved:

tty: Fix ou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47383</guid>
    <pubDate>Tue, 21 May 2024 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47383</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tty: Fix out-of-bound vmalloc access in imageblit  This issue happens when a userspace program does an ioctl FBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct containing only the fields xres, yres, and bits_per_pixel with values.  If this struct is the same as the previous ioctl, the vc_resize() detects it and doesn't cal…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1203 – The Conversios – Google Analytics 4 (GA4), Meta Pixel &amp; more Via Google Tag Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1203</guid>
    <pubDate>Wed, 13 Mar 2024 16:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1203</strong></p>
  <p>The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'valueData' parameter in all versions up to, and including, 7.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0786 – The Conversios – Google Analytics 4 (GA4), Meta Pixel &amp; more Via Google Tag Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0786</guid>
    <pubDate>Wed, 28 Feb 2024 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0786</strong></p>
  <p>The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncProductCategory function using the parameters conditionData, valueData, productArray, exclude and include in all versions up to, and including, 7.0.7 due to insufficient escaping on the user supplied parameter and lack of…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22393 – Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22393</guid>
    <pubDate>Thu, 22 Feb 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22393</strong></p>
  <p>Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.  Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48421 – In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48421</guid>
    <pubDate>Fri, 08 Dec 2023 16:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48421</strong></p>
  <p>In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48409 – In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48409</guid>
    <pubDate>Fri, 08 Dec 2023 16:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48409</strong></p>
  <p>In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49464 – libheif v1.17.5 was discovered to contain a segmentation violation via the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49464</guid>
    <pubDate>Thu, 07 Dec 2023 20:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49464</strong></p>
  <p>libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46352 – In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46352</guid>
    <pubDate>Thu, 02 Nov 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46352</strong></p>
  <p>In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / su…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46094 – Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46094</guid>
    <pubDate>Thu, 26 Oct 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46094</strong></p>
  <p>Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-32653 – An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32653</guid>
    <pubDate>Mon, 25 Sep 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-32653</strong></p>
  <p>An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34153 – A vulnerability was found in ImageMagick. This security flaw causes a shell comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34153</guid>
    <pubDate>Tue, 30 May 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34153</strong></p>
  <p>A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22845 – An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22845</guid>
    <pubDate>Thu, 30 Mar 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22845</strong></p>
  <p>An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-42498 – In Pixel cellular firmware, there is a possible out of bounds write due to a mis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42498</guid>
    <pubDate>Fri, 24 Mar 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-42498</strong></p>
  <p>In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-240662453References: N/A</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20607 – In the Pixel cellular firmware, there is a possible out of bounds write due to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20607</guid>
    <pubDate>Fri, 16 Dec 2022 16:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20607</strong></p>
  <p>In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238914868References: N/A</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0284 – A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0284</guid>
    <pubDate>Mon, 29 Aug 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0284</strong></p>
  <p>A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3610 – A heap-based buffer overflow vulnerability was found in ImageMagick in versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3610</guid>
    <pubDate>Thu, 24 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3610</strong></p>
  <p>A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-24922 – The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-24922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-24922</guid>
    <pubDate>Mon, 13 Dec 2021 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-24922</strong></p>
  <p>The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23981 – A texture upload of a Pixel Buffer Object could have confused the WebGL code to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23981</guid>
    <pubDate>Wed, 31 Mar 2021 14:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23981</strong></p>
  <p>A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26825 – An integer overflow issue exists in Godot Engine up to v3.2 that can be triggere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26825</guid>
    <pubDate>Mon, 08 Feb 2021 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26825</strong></p>
  <p>An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to Dynamic stack buffer overflow. Depending on the context of the application, attack ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-0434 – In Pixel's use of the Catpipe library, there is possible memory corruption due t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-0434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-0434</guid>
    <pubDate>Thu, 17 Sep 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-0434</strong></p>
  <p>In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150730508</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-6100 – An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6100</guid>
    <pubDate>Mon, 20 Jul 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-6100</strong></p>
  <p>An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerability. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability potentially could be triggered from guest machines running virtualization environments (ie. VMware, qemu, Vi…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5183 – An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5183</guid>
    <pubDate>Sat, 25 Jan 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5183</strong></p>
  <p>An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affec…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5147 – An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL drive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5147</guid>
    <pubDate>Sat, 25 Jan 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5147</strong></p>
  <p>An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5146 – An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL drive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5146</guid>
    <pubDate>Sat, 25 Jan 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5146</strong></p>
  <p>An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5124 – An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL drive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5124</guid>
    <pubDate>Sat, 25 Jan 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5124</strong></p>
  <p>An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5098 – An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL drive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5098</guid>
    <pubDate>Thu, 05 Dec 2019 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5098</strong></p>
  <p>An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5049 – An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5049</guid>
    <pubDate>Thu, 31 Oct 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5049</strong></p>
  <p>An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5521 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5521</guid>
    <pubDate>Fri, 20 Sep 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5521</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to cr…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13299 – ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13299</guid>
    <pubDate>Fri, 05 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13299</strong></p>
  <p>ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13298 – ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13298</guid>
    <pubDate>Fri, 05 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13298</strong></p>
  <p>ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-9567 – On Pixel devices there is a bug causing verified boot to show the same certifica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9567</guid>
    <pubDate>Thu, 06 Dec 2018 14:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-9567</strong></p>
  <p>On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different signing keys. This may lead to local escalation of privilege if people are relying on those fingerprints to determine what version of the OS the device is running, with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11263 – In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11263</guid>
    <pubDate>Thu, 06 Sep 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11263</strong></p>
  <p>In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats received for each radio from FW. If the radio_id received from the FW is greater than or equal to maximum, an OOB write will occur. On supported Google Pixel and Nexus devices, this has been addressed…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-5160 – WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5160</guid>
    <pubDate>Mon, 11 Jun 2018 21:29:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-5160</strong></p>
  <p>WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9077 – Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9077</guid>
    <pubDate>Mon, 11 Jun 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9077</strong></p>
  <p>Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11813 – libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11813</guid>
    <pubDate>Wed, 06 Jun 2018 03:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11813</strong></p>
  <p>libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10112 – An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_const...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10112</guid>
    <pubDate>Mon, 16 Apr 2018 09:58:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10112</strong></p>
  <p>An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_constructed function in buffer/gegl-tile-backend-swap.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PNG file that is mishandled during a call to the babl_format_get_bytes_per_pixel function in babl-format.c in babl 0.1.46.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6251 – NVIDIA Windows GPU Display Driver contains a vulnerability in the DirectX 10 Use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6251</guid>
    <pubDate>Mon, 02 Apr 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6251</strong></p>
  <p>NVIDIA Windows GPU Display Driver contains a vulnerability in the DirectX 10 Usermode driver, where a specially crafted pixel shader can cause writing to unallocated memory, leading to denial of service or potential code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-13247 – In the Pixel 2 bootloader, there is a missing permission check which bypasses ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-13247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-13247</guid>
    <pubDate>Mon, 12 Feb 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-13247</strong></p>
  <p>In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-71486645.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-13247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6799 – The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6799</guid>
    <pubDate>Wed, 07 Feb 2018 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6799</strong></p>
  <p>The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17786 – In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17786</guid>
    <pubDate>Wed, 20 Dec 2017 09:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17786</strong></p>
  <p>In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-0866 – An elevation of privilege vulnerability in the Direct rendering infrastructure o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-0866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-0866</guid>
    <pubDate>Thu, 16 Nov 2017 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-0866</strong></p>
  <p>An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-38415808. References: N-CVE-2017-0866.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-0866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6275 – An information disclosure vulnerability exists in the Thermal Driver, where a mi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6275</guid>
    <pubDate>Tue, 14 Nov 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6275</strong></p>
  <p>An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-6274 – An elevation of Privilege vulnerability exists in the Thermal Driver, where a mi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6274</guid>
    <pubDate>Tue, 14 Nov 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-6274</strong></p>
  <p>An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds checks in the thermal throttle driver can cause an out-of-bounds write in the kernel. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-34705801. References: N-CVE-2017-6274.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16669 – coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16669</guid>
    <pubDate>Thu, 09 Nov 2017 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16669</strong></p>
  <p>coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-11271 – Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 201...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11271</guid>
    <pubDate>Fri, 11 Aug 2017 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-11271</strong></p>
  <p>Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transfer of pixel blocks. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-11234 – Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 201...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11234</guid>
    <pubDate>Fri, 11 Aug 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-11234</strong></p>
  <p>Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF data related to the way how the components of each pixel are stored. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11641 – GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11641</guid>
    <pubDate>Wed, 26 Jul 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11641</strong></p>
  <p>GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5507 – Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5507</guid>
    <pubDate>Fri, 24 Mar 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5507</strong></p>
  <p>Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6520 – Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6520</guid>
    <pubDate>Tue, 13 Dec 2016 15:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6520</strong></p>
  <p>Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5691 – The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5691</guid>
    <pubDate>Tue, 13 Dec 2016 15:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5691</strong></p>
  <p>The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5691">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
