CVE-2020-27774
- EPSS 0.09%
- Veröffentlicht 04.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:48
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lea...
CVE-2020-27775
- EPSS 0.09%
- Veröffentlicht 04.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:48
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely le...
CVE-2020-27776
- EPSS 0.07%
- Veröffentlicht 04.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:48
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely ...
CVE-2020-27765
- EPSS 0.09%
- Veröffentlicht 04.12.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:21:47
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to applic...
CVE-2020-27767
- EPSS 0.09%
- Veröffentlicht 04.12.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:21:47
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would...
CVE-2020-27771
- EPSS 0.11%
- Veröffentlicht 04.12.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:21:48
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type t...
CVE-2020-27778
- EPSS 0.28%
- Veröffentlicht 03.12.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:49
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a deni...
CVE-2020-27783
- EPSS 1.25%
- Veröffentlicht 03.12.2020 17:15:13
- Zuletzt bearbeitet 17.12.2025 21:15:52
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbit...
CVE-2020-14339
- EPSS 0.08%
- Veröffentlicht 03.12.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:02
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest ...
CVE-2020-14351
- EPSS 0.13%
- Veröffentlicht 03.12.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:04
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulne...