CVE-2020-27790
- EPSS 0.05%
- Veröffentlicht 18.08.2022 19:15:14
- Zuletzt bearbeitet 11.04.2025 12:27:55
A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The h...
CVE-2020-27787
- EPSS 0.05%
- Veröffentlicht 18.08.2022 19:15:14
- Zuletzt bearbeitet 11.04.2025 12:27:55
A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
CVE-2021-30501
- EPSS 0.13%
- Veröffentlicht 27.05.2021 00:15:08
- Zuletzt bearbeitet 11.04.2025 12:27:55
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
CVE-2021-30500
- EPSS 0.16%
- Veröffentlicht 27.05.2021 00:15:08
- Zuletzt bearbeitet 11.04.2025 12:27:55
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.
CVE-2020-24119
- EPSS 0.38%
- Veröffentlicht 14.05.2021 21:15:07
- Zuletzt bearbeitet 11.04.2025 12:27:55
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2021-20285
- EPSS 0.24%
- Veröffentlicht 26.03.2021 17:15:13
- Zuletzt bearbeitet 11.04.2025 12:27:55
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from...
CVE-2019-20805
- EPSS 0.17%
- Veröffentlicht 01.06.2020 14:15:09
- Zuletzt bearbeitet 11.04.2025 12:27:55
p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.
CVE-2019-20053
- EPSS 0.37%
- Veröffentlicht 27.12.2019 22:15:11
- Zuletzt bearbeitet 11.04.2025 12:27:55
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
CVE-2019-20051
- EPSS 0.32%
- Veröffentlicht 27.12.2019 22:15:11
- Zuletzt bearbeitet 11.04.2025 12:27:55
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.
CVE-2019-20021
- EPSS 0.34%
- Veröffentlicht 27.12.2019 02:15:10
- Zuletzt bearbeitet 11.04.2025 12:27:55
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.