Python

Pillow

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.2%
  • Veröffentlicht 04.10.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:13

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

  • EPSS 0.46%
  • Veröffentlicht 24.04.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

  • EPSS 0.57%
  • Veröffentlicht 04.11.2016 10:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

  • EPSS 0.36%
  • Veröffentlicht 04.11.2016 10:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

  • EPSS 3.5%
  • Veröffentlicht 13.04.2016 16:59:25
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

  • EPSS 1.18%
  • Veröffentlicht 13.04.2016 16:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

  • EPSS 1.37%
  • Veröffentlicht 13.04.2016 16:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.

  • EPSS 0.15%
  • Veröffentlicht 13.04.2016 16:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.

  • EPSS 0.4%
  • Veröffentlicht 01.05.2015 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.

  • EPSS 1.08%
  • Veröffentlicht 16.01.2015 16:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.