CVE-2020-27845
- EPSS 0.07%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:55
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw ...
CVE-2020-27841
- EPSS 0.08%
- Veröffentlicht 05.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:54
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to...
CVE-2020-15389
- EPSS 0.27%
- Veröffentlicht 29.06.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:05:28
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to c...
CVE-2020-15358
- EPSS 0.04%
- Veröffentlicht 27.06.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:24
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
CVE-2020-13632
- EPSS 0.03%
- Veröffentlicht 27.05.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
- EPSS 0.08%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
CVE-2020-13631
- EPSS 0.09%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
CVE-2020-13434
- EPSS 0.05%
- Veröffentlicht 24.05.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:15
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-2783
- EPSS 0.98%
- Veröffentlicht 15.04.2020 14:15:27
- Zuletzt bearbeitet 21.11.2024 05:26:15
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access ...
CVE-2020-2784
- EPSS 0.93%
- Veröffentlicht 15.04.2020 14:15:27
- Zuletzt bearbeitet 21.11.2024 05:26:15
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network acce...