CVE-2020-27844
- EPSS 1.99%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:55
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerabili...
CVE-2020-27845
- EPSS 0.11%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:55
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw ...
CVE-2020-27841
- EPSS 0.31%
- Veröffentlicht 05.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:54
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to...
CVE-2020-36158
- EPSS 0.58%
- Veröffentlicht 05.01.2021 05:15:10
- Zuletzt bearbeitet 21.11.2024 05:28:50
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
CVE-2019-25013
- EPSS 0.81%
- Veröffentlicht 04.01.2021 18:15:13
- Zuletzt bearbeitet 09.06.2025 16:15:30
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
CVE-2020-24386
- EPSS 2.24%
- Veröffentlicht 04.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:43
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
CVE-2020-25275
- EPSS 3.36%
- Veröffentlicht 04.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:17:50
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
CVE-2020-35965
- EPSS 1.62%
- Veröffentlicht 04.01.2021 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:28:36
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
CVE-2020-12658
- EPSS 0.57%
- Veröffentlicht 31.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:00
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't ma...
CVE-2019-15523
- EPSS 0.67%
- Veröffentlicht 30.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:28:55
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.