CVE-2020-36281
- EPSS 0.51%
- Veröffentlicht 12.03.2021 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
CVE-2020-36278
- EPSS 0.54%
- Veröffentlicht 12.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
CVE-2020-36279
- EPSS 4.25%
- Veröffentlicht 12.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
CVE-2021-28153
- EPSS 0.57%
- Veröffentlicht 11.03.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:11
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which coul...
CVE-2020-36277
- EPSS 6.65%
- Veröffentlicht 11.03.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
CVE-2021-21381
- EPSS 0.12%
- Veröffentlicht 11.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:14
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to ga...
CVE-2021-21375
- EPSS 1.31%
- Veröffentlicht 10.03.2021 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:13
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when tw...
CVE-2021-21772
- EPSS 1.67%
- Veröffentlicht 10.03.2021 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:48:56
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerab...
- EPSS 16.4%
- Veröffentlicht 10.03.2021 08:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:11
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to u...
CVE-2020-13959
- EPSS 3.21%
- Veröffentlicht 10.03.2021 08:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:14
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being execut...