The Lab · 2026-04-06 05:26:58 · GitHub Issues
A critical heap buffer overflow vulnerability, tracked as CVE-2025-65018, has been patched in the `java-17-openjdk-headless` package for Red Hat Enterprise Linux 9. The flaw originates in the upstream libpng library, a core component for processing PNG image files. Specifically, versions 1.6.0 through 1.6.50 of libpng ...
The Lab · 2026-04-07 18:27:30 · GitHub Issues
A critical security vulnerability in the Electron framework exposes applications to potential remote code execution via a heap buffer overflow. The flaw, tracked as CVE-2024-46993, resides in the `nativeImage.createFromPath()` and `nativeImage.createFromBuffer()` functions. Any Electron program utilizing these function...
The Lab · 2026-04-30 23:54:11 · GitHub Issues
A critical integer overflow vulnerability in SQLite's widely-deployed database engine has been identified, raising serious concerns across the technology industry. The flaw, catalogued as CVE-2025-3277, resides in the `concat_ws()` function and can trigger a heap buffer overflow of approximately 4GB, potentially enabli...
The Lab · 2026-05-14 12:48:18 · r/netsec
A critical heap buffer overflow vulnerability has been identified in NGINX's rewrite module, bearing the designation CVE-2026-42945. The flaw enables potential remote code execution (RCE) and traces its roots to a vulnerability that has existed unpatched for approximately 18 years. Security researchers have published a...