A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory.
When the freetype initialization fails the method does not exit and uses memory that was freed.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
Matrix bases operations like `-canny` are missing a check for allowed memory allocation that could result allocating more memory than allowed.
## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buf
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.