hugin
by hugin
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-25446 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2024 | An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | ||
| CVE-2024-25445 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2024 | Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure. | ||
| CVE-2024-25443 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2024 | An issue in the HuginBase::ImageVariable::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image. | ||
| CVE-2024-25442 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2024 | An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | ||
| CVE-2026-63769 | Hig | 0.00 | 7.7 | 0.00 | Jul 20, 2026 | Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via… | ||
| CVE-2007-5200 | 0.00 | — | 0.00 | Oct 14, 2007 | hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file. |
- risk 0.51cvss 7.8epss 0.00
An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.
- risk 0.51cvss 7.8epss 0.00
Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
- risk 0.51cvss 7.8epss 0.00
An issue in the HuginBase::ImageVariable::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.
- risk 0.51cvss 7.8epss 0.00
An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.
- risk 0.00cvss 7.7epss 0.00
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via…
- CVE-2007-5200Oct 14, 2007risk 0.00cvss —epss 0.00
hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.