<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:38:08.689642+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4149</id>
    <title>ALSA-2021:4149 — Moderate: python-pillow security update</title>
    <updated>2026-10-03T23:38:08.955334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-pillow</p>
<p>The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.</p>
<p>Security Fix(es):</p>
<p>* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)</p>
<p>* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)</p>
<p>* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)</p>
<p>* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)</p>
<p>* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)</p>
<p>* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)</p>
<p>* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)</p>
<p>* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)</p>
<p>* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)</p>
<p>* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)</p>
<p>* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)</p>
<p>* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)</p>
<p>* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)</p>
<p>* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)</p>
<p>* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05313</id>
    <title>bdu:2021-05313</title>
    <updated>2026-10-03T23:38:08.955467+00:00</updated>
    <content>bdu:2021-05313</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-pillow-2021-28677</id>
    <title>BIT-pillow-2021-28677</title>
    <updated>2026-10-03T23:38:08.955493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: pillow</p>
<p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-pillow-2021-28677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-28677</id>
    <title>BREW-pillow-CVE-2021-28677</title>
    <updated>2026-10-03T23:38:08.955530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pillow</p>
<p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-28677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-54031</id>
    <title>cnvd-2021-54031</title>
    <updated>2026-10-03T23:38:08.955581+00:00</updated>
    <content>cnvd-2021-54031</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-54031"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26058</id>
    <title>EUVD-2026-26058</title>
    <updated>2026-10-03T23:38:08.955627+00:00</updated>
    <content>EUVD-2026-26058</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28677</id>
    <title>fkie_cve-2021-28677</title>
    <updated>2026-10-03T23:38:08.955646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q5hq-fp76-qmrc</id>
    <title>GHSA-q5hq-fp76-qmrc — Uncontrolled Resource Consumption in Pillow</title>
    <updated>2026-10-03T23:38:08.955684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q5hq-fp76-qmrc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28677</id>
    <title>gsd-2021-28677</title>
    <updated>2026-10-03T23:38:08.955725+00:00</updated>
    <content>gsd-2021-28677</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-93</id>
    <title>PYSEC-2021-93</title>
    <updated>2026-10-03T23:38:08.955746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-93"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4149</id>
    <title>RHSA-2021:4149 — Red Hat Security Advisory: python-pillow security update</title>
    <updated>2026-10-03T23:38:08.955769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-pillow: Buffer over-read in PCX image reader python-pillow: Buffer over-read in SGI RLE image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Negative-offset memcpy in TIFF image reader python-pillow: Regular expression DoS in PDF format parser python-pillow: Out-of-bounds read in SGI RLE image reader python-pillow: Excessive memory allocation in BLP image reader python-pillow: Excessive memory allocation in ICNS image reader python-pillow: Excessive memory allocation in ICO image reader python-pillow: Excessive memory allocation in PSD image reader python-pillow: Infinite loop in FLI image reader python-pillow: Excessive CPU use in EPS image reader python-pillow: Excessive looping in BLP image reader python-pillow: Buffer overflow in image convert function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</id>
    <title>SUSE-SU-2021:1938-1 — Security update for python-Pillow</title>
    <updated>2026-10-03T23:38:08.955812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28677</id>
    <title>UBUNTU-CVE-2021-28677</title>
    <updated>2026-10-03T23:38:08.955836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2</p>
<p>An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</id>
    <title>WID-SEC-W-2022-1835 — Red Hat Enterprise Linux (python-pillow): Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:38:08.955862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835"/>
  </entry>
</feed>
