rpm package
opensuse/libXpm&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libXpm&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-94287 | Med | 5.5 | < 3.5.18-3.1 | 3.5.18-3.1 | Sep 28, 2026 | A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion. | |
| CVE-2026-4367 | Med | 5.5 | < 3.5.18-2.1 | 3.5.18-2.1 | Jun 16, 2026 | A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an inter |
- affected < 3.5.18-3.1fixed 3.5.18-3.1
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
- affected < 3.5.18-2.1fixed 3.5.18-2.1
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an inter