VYPR

Affinity by Canva

by Canva

CVEs (4)

  • CVE-2026-96396MedOct 9, 2026
    risk 0.32cvss 4.9epss —

    The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A…

  • CVE-2026-96395LowOct 9, 2026
    risk 0.23cvss 3.6epss —

    The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document…

  • CVE-2026-96393LowOct 9, 2026
    risk 0.23cvss 3.6epss —

    The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity,…

  • CVE-2026-96394LowOct 9, 2026
    risk 0.19cvss 2.9epss —

    The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat…