Vendor
Use-After-Free Vulnerability in librsvg
1 CVEA use-after-free vulnerability in librsvg (CVE-2026-96889) allows remote attackers to trigger memory corruption and potential code execution by providing specially crafted SVG documents.
Denial of Service Vulnerability in libxml2
1 TTP 1 CVEA vulnerability in the libxml2 library allows a remote, unauthenticated attacker to trigger a denial of service condition through the submission of malformed XML data.
Local Privilege Escalation in gvfsd-admin via TOCTOU Race Condition
1 TTP 1 CVEA Time-of-Check Time-of-Use (TOCTOU) race condition in the gvfsd-admin daemon allows local attackers to perform privilege escalation by manipulating symbolic links to modify ownership of arbitrary system files.
Multiple Vulnerabilities in libxml2 Library
1 TTPMultiple vulnerabilities within the libxml2 library could allow remote attackers to bypass security restrictions, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.
Heap Use-After-Free in libsoup HTTP/2 Implementation
1 TTP 1 CVEA heap use-after-free vulnerability in the libsoup HTTP/2 client allows malicious servers or MITM attackers to trigger memory corruption via specifically timed GOAWAY frames during file uploads.
Heap-Based Buffer Overflow in gvfs SFTP Backend
1 CVEThe gvfsd-sftp process contains a heap-based buffer overflow vulnerability that allows a malicious SFTP server to corrupt memory via crafted file read responses.
Potential Privilege Escalation via SUID/SGID Proxy Execution on Linux
1 rule 4 TTPsAttackers may exploit SUID/SGID binaries like pkexec, su, or sudo on Linux systems to execute commands with elevated privileges, by identifying instances where a process runs with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, allowing a low-privilege foothold to gain full system control.
Libsoup HTTP/2 Frame Window Exhaustion Remote Denial of Service
1 CVEA remote denial of service vulnerability, CVE-2026-15713, exists in the soupcache component of the Libsoup library due to a memory leak that leads to HTTP/2 frame window exhaustion, potentially causing application crashes or unresponsiveness.
CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS
2 TTPs 1 CVEAn integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE
1 CVEA high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.
Potential Proxy Execution via Systemd-run on Linux
1 rule 3 TTPsThis brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.
CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE
3 TTPs 1 CVEA heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.