-Infinity
0

Gnome libsoupLibsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels

Risk 37
Severity
6.5
First published (updated )

Gnome libsoupLibsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()

Risk 40
Severity
6.5
First published (updated )

Gnome libsoupAfter a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-…

Risk 19
Severity
4
First published (updated )

Gnome libsoupAn unsigned integer underflow in soup_filter_input_stream_read_until() in libsoup/soup-filter-input-…

Risk 19
Severity
4
First published (updated )

Gnome libsoupThe chunked transfer encoding parser in libsoup uses strtoul(metabuf, NULL, 16) to parse chunk sizes…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gnome libsoupLibsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string

Risk 40
Severity
6.5
First published (updated )

Gnome libsoupLibsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGimp: gimp: denial of service via integer overflow in playstation tim loader

Risk 31
Severity
5.5
First published (updated )

Gnome GIMPhttps://gitlab.gnome.org/GNOME/gimp/-/work_items/16493 PlayStation TIM loader computes CLUT size as…

Risk 19
Severity
4
First published (updated )

redhat Enterprise LinuxYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

Risk 66
Severity
9.1
First published (updated )

Gnome GIO (g_dbus_node_info_new_for_xml / gdbusintrospection)A state confusion vulnerability exists in g_dbus_node_info_new_for_xml() in gio/gdbusintrospection.c…

Risk 33
Severity
7
First published (updated )

redhat Enterprise LinuxGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

Risk 64
Severity
8.6
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Risk 54
Severity
8.2
First published (updated )

Gnome GLibA heap-buffer-overflow READ vulnerability exists in GLib's g_regex_replace() function when used with…

Risk 19
Severity
4
First published (updated )

redhat Enterprise LinuxGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()

Risk 54
Severity
8.2
First published (updated )

Gnome GLibgvs_tuple_is_normal() in glib/gvariant-serialiser.c:1253 has an off-by-one error in its alignment pa…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerFFmpeg fixes PixelSmash flaw in widely used video decoder

First published (updated )

oss-secCVE-2026-6653: libxml2: use after fe in xmlParseInternalSubset (>=2.9.11, <2.11.0)

Gnome libxml2libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling

Risk 86
Severity
7
First published (updated )

redhat Enterprise LinuxLibsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver

Risk 32
Severity
4.8
First published (updated )

Gnome libsouphttps://gitlab.gnome.org/GNOME/libsoup/-/work_items/516 https://redhat.atlassian.net/browse/PSIRTSUP…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gnome libsoupLibsoup: heap out-of-bounds read in libsoup due to integer truncation

Risk 28
Severity
4.2
First published (updated )

Gnome libsoupLibsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

Risk 17
Severity
3.4
First published (updated )

Gnome libsoupLibsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)

Risk 32
Severity
4.8
First published (updated )

oss-secEvince/Atril/Xader command injection CVE-2026-46529

oss-secEvince/Atril/Xader command injection CVE-2026-46529

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203